Normally when services offer users TOTP (time-based rotating codes) as their additional authentication factor, a handful of static, non-expiring backup codes are also generated and provided to the user.
I just setup my PDC Keycloak account with TOTP, and was not offered these codes. We should see if Keycloak supports them, and be sure we're providing them to users during setup.
Step one is verifying Keycloak supports this; if not (and if it can't be added through some sort of extension or library), then let's just close this.
Normally when services offer users TOTP (time-based rotating codes) as their additional authentication factor, a handful of static, non-expiring backup codes are also generated and provided to the user.
I just setup my PDC Keycloak account with TOTP, and was not offered these codes. We should see if Keycloak supports them, and be sure we're providing them to users during setup.
Step one is verifying Keycloak supports this; if not (and if it can't be added through some sort of extension or library), then let's just close this.