Change record status: 
Introduced in branch: 
2.x
Introduced in version: 
2.0
Description: 

In previous version of TFA the included plugins for TOTP, HOTP and Recovery Code plugins will no longer store a hashed copy of accepted codes.

The TOTP and HOTP plugins have since 8.x-1.3 have stored an incremental counter to prevent token reuse rendering the storing of codes to no longer be necessary.

The Recovery Codes plugin has always removed codes once utilized.

As part of the upgrade if a user has not previously logged in with a version of TFA newer than 8.x-1.3 the update will locate the most recent stored token, add the accepted codes window period to ensure previous codes are not re-used. Sites that use a large time window or did not previously upgrade to 8.x-1.3 may experience a temporary lockout until the time period has elapsed.

Impacts: 
Site builders, administrators, editors