Skip to content

feat(FOUR-28542): Authenticator app option still available even the user has already configured it. - #9058

Open
rodriquelca wants to merge 4 commits into
developfrom
feature/FOUR-28542
Open

rodriquelca wants to merge 4 commits into
developfrom
feature/FOUR-28542

Conversation

@rodriquelca

@rodriquelca rodriquelca commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Issue & Reproduction Steps

Issue: On the 2FA login screen, the Authenticator app link and QR setup remain available after a user has already configured Google Authenticator. Anyone with access to the login session can register a new device and pass 2FA.

Repro:

Admin → Settings → Log-In Options: enable Require Two Step Authentication and select Authenticator App
Log in with a regular user (not SSO)
On /2fa, click Authenticator app → scan QR with Google Authenticator → enter code → enter the app
Log out and log in again
Actual: Authenticator app link still appears; QR can be scanned again on another device.
Expected: Link appears only on first setup; later logins only ask for the code. Admin can reset configuration.

Solution

  • Added auth_app_configured_at on users to track one-time authenticator setup
  • Hide Authenticator app on /2fa when the user is already configured
  • Block /2fa/auth_app_qr when already configured
  • Set auth_app_configured_at after the first valid 6-digit authenticator code
  • Added Reset Authenticator App button in Admin → Users → Edit (sidebar)
  • Added API PUT /api/1.0/users/{user}/reset_auth_app for admin reset
app_auth.mov

How to Test

  1. Configure 2FA with Authenticator App (steps above)
  2. First login: confirm Authenticator app link is visible → complete setup
  3. Second login: confirm link is hidden; only code field shows
  4. Admin → Users → Edit → click Reset Authenticator App
  5. Login again: link should appear once more for re-enrollment

Related Tickets & Packages

Code Review Checklist

  • I have pulled this code locally and tested it on my instance, along with any associated packages.
  • This code adheres to ProcessMaker Coding Guidelines.
  • This code includes a unit test or an E2E test that tests its functionality, or is covered by an existing test.
  • This solution fixes the bug reported in the original ticket.
  • This solution does not alter the expected output of a component in a way that would break existing Processes.
  • This solution does not implement any breaking changes that would invalidate documentation or cause existing Processes to fail.
  • This solution has been tested with enterprise packages that rely on its functionality and does not introduce bugs in those packages.
  • This code does not duplicate functionality that already exists in the framework or in ProcessMaker.
  • This ticket conforms to the PRD associated with this part of ProcessMaker.

ci:deploy

@cursor

cursor Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes authentication enrollment state and admin reset paths; behavior is covered by feature tests but touches security-sensitive login flows.

Overview
Fixes a 2FA gap where the Authenticator app link and QR setup stayed available after enrollment, allowing extra devices to be registered during an active login session.

Adds auth_app_configured_at on users to record one-time setup. The OTP screen and QR route are shown only when the user has authenticator 2FA enabled but is not yet enrolled; a successful 6-digit app code sets the timestamp. Username changes clear enrollment (secrets are username-bound). Create/update APIs and the admin user form strip auth_app_configured_at so stale snapshots cannot forge or clear enrollment; only PUT users/{user}/reset_auth_app (plus admin Reset Authenticator App in user edit) clears it for re-enrollment.

Reviewed by Cursor Bugbot for commit f65514e. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread ProcessMaker/TwoFactorAuthentication.php
@nolanpro

Copy link
Copy Markdown
Contributor

QA server K8S was successfully deployed https://ci-0e68e8357e.engk8s.processmaker.net

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit c9767f4. Configure here.

Comment thread ProcessMaker/Models/User.php Outdated
@decisions-sonarqube

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants