polonel / trudesk

:coffee: :seedling: Trudesk is an open-source help desk/ticketing solution.
http://trudesk.io
Other
1.29k stars 430 forks source link

Bypass of 2FA when using mobile version #635

Open eboss-dev opened 12 months ago

eboss-dev commented 12 months ago

Is this a BUG REPORT or FEATURE REQUEST?:

What happened: I tried setting up the 2FA with Duo. It works fine as long as I use the desktop version. When I switch to the mobile one the 2FA is completely by-passed

What did you expect to happen: 2FA working in the mobile version too

How to reproduce it (as minimally and precisely as possible): I try to reproduce using a phone without the authenticator as well as in chrome with the inspection tool emulating a phone. When I am at this path (yourTrudeskURL/mobile/#/login) I don't get the request for a code.

Anything else we need to know?:

Environment:

github-actions[bot] commented 11 months ago

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

polonel commented 10 months ago

The mobile view is being rewritten. It currently uses an outdated view of ionic and is completely broken. Mobile view will be disabled in an upcoming release while the rewrite occurs.