whythawk / hrd

0 stars 2 forks source link

2-factor login recognised but not completing login. #86

Closed ratkins5 closed 9 years ago

ratkins5 commented 9 years ago

On providing the 2-factor login number, account login recognises it but doesn't actually log you in. Then gives you: https://hrdrelocation.eu/en/user/ga_check

tobes commented 9 years ago

Can you provide more detail on this. I need to be able to reproduce the issue to fix it.

From what I can see things are working as expected and I can log in etc

ratkins5 commented 9 years ago

I'll try: I go through the normal login process, and once I've entered the (correct) six digit code the dialog box goes away but the login has not completed. To test this, if I enter a deliberately wrong code the dialogue box remains, and informs me the code is incorrect. To check this I got Gavin to set up his desktop (I'm using my iPhone) as the authentication device, same result. What happens if you use my login and password (not sure if you have/ can get them?).

tobes commented 9 years ago

can you please answer this like i'm an idiot.

I go through the normal login process

this is too vague - also did you successfully set up the 2 factor id in the first place?

ratkins5 commented 9 years ago

Sorry. Yes, I set up google authenticator on my iPhone. Because I wasn't sure I was doing this right Gavin set up 2-factor of my username and password on his desktop as well (so we have 2 devices capable of generating codes). Starting at the homepage I fill in the hrd, hrdaccess dialogue box to see the site. I click 'login' and up comes the dialogue box. I enter my username and password. It accepts these and requests the 6-digit code. I enter this and a) if I've entered it wrong the dialogue box remains, and tells me the code is wrong, or b) if I've entered it correctly the dialogue box disappears but I am not shown as logged in, and can't see items such as the message board that require login to display.

tobes commented 9 years ago

can you add a screen shot after you give the correct code.

ratkins5 commented 9 years ago

screen shot 2015-02-16 at 10 15 28

ratkins5 commented 9 years ago

Not sure how helpful that is...

tobes commented 9 years ago

very it shows you are not logged in

can you show me the verification page now

ratkins5 commented 9 years ago

screen shot 2015-02-16 at 10 19 51

ratkins5 commented 9 years ago

Got to go out for an hour now, but back 11:30-ish.

tobes commented 9 years ago

and you click continue button NOT press enter?

ratkins5 commented 9 years ago

Can't now be sure. Trying it again and you're right, pressing return puts me to the not-logged-in screen, as if I'd cancelled. 6-digit codes not working now. Going to try this again with Gavin's desktop.

ratkins5 commented 9 years ago

OK, I'm getting there now. It's the clock on my iPhone. It wasn't set to automatic, therefore the time stamp on my authenticator code was always wrong. Gavin's clock was on automatic, hence no problems with his. Once I set my time automatic it worked a dream. This is not a software issue for you, but an FAQ for me to advise the client. Thanks for following up though, I wouldn't otherwise have identified the issue.