As a site administrator, I would like to be able to bypass my the TFA setup password checks in the case where initial authentication is handled by a Drupal passwordless system like shibauth.
This builds upon the patch to TFA here https://www.drupal.org/project/tfa/issues/2979978
No harm in declining this, it can just reside here as a possible patch for anyone else facing the use case I have described.
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | bypass-password-checks-at-setup-2979983-2.patch | 5.81 KB | swirt |
Comments
Comment #2
swirtThis patch merely allows the password verification to by bypassed if the bypass has been enabled.
It does account for the possibility where without a password check, anyone could change anyone elses' TFA application.
Comment #3
damienmckennaAs a reminder, the "assigned" field should be set to "unassigned" when you're done working on changes - it's for indicating you're actively working on something, so if you're done it's polite to reset it. Thanks :)