-
Notifications
You must be signed in to change notification settings - Fork 55
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Setup new TOTP without disabling #678
Comments
I would appreciate such an option as well. unfortunately same request was rejected some time ago #158 |
@ChristophWurst I agree the request isn't exact the same. From the wording 'setup new TOTP' I understood what I looked for.. In general only one TOTP code is not ideal - the user can't pair multiple devices - like phone and tablet - for TOTP (or has to pair them at same time). Other platforms like Google and Microsoft allow multiple TOTP devices - Nextcloud with Webauthn as well - why it is impossible to have multiple TOTP identified by friendly device name which could be invalidated one by one once the user stops using specific device? |
Proof? At least for Google I find official and unofficial sources that say you need to reset TOTP and scan the QR code with all your devices at once. Like exactly how you can set up more than one device here. |
I use hardware and an authenticator app as backup in case I left my usb key at home. I would love to have the same way on nextcloud too. |
I know this is just a workaraound. But the initial QR code is just a letter/number string, which by the way is also displayed in plain text during the initial setup. This key can be copied and stored in a secure place (e.g. KeePass) and then used with as many TOTP apps and HW keys as you want. Also, many TOTP apps like for example andOTP on Android do have a backup function. This makes it very easy to transfer the codes to a new device without having to change anything in the corresponding accounts. |
@obrb that's how I currently work around that issue as well. Still not something I would trust an end-user with. |
I just had to move all my TOTP codes to my new phone.
However in order to do this I have to disable and re-enable the TOTP setting.
While valid it does feel a little... counter intuitive.
I'd prefer a button 'setup new TOTP' or whatever that guides us trough the wizard again (also warning previous codes are invalid). Would feel a bit more user friendly IMO.
The text was updated successfully, but these errors were encountered: