From a7f94af9cf5b6e557378f23ca2a987ba08bfa9ae Mon Sep 17 00:00:00 2001 From: Andre Klapper Date: Tue, 20 May 2025 14:08:59 +0200 Subject: [PATCH] Explain consequences when adding second Multi-Factor Auth Summary: Warn users who already have MFA set up that adding a second Multi-Factor Auth will require entering both instead of being able to choose from one of them. This is currently not clear. I was surprised by this, now I have another user also surprised. Closes T16081 Test Plan: 1. As an admin, set up TOTP as an auth provider at http://phorge.localhost/auth/mfa/ 2. As a user, add a first TOTP auth factor at http://phorge.localhost/settings/panel/multifactor/ 3. As a user, try to add a second TOTP auth factor and see an additional sentence in the dialog Reviewers: O1 Blessed Committers, valerio.bozzolan Reviewed By: O1 Blessed Committers, valerio.bozzolan Subscribers: mainframe98, tobiaswiese, valerio.bozzolan, Matthew, Cigaryno Maniphest Tasks: T16081 Differential Revision: https://we.phorge.it/D26028 --- .../panel/PhabricatorMultiFactorSettingsPanel.php | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/src/applications/settings/panel/PhabricatorMultiFactorSettingsPanel.php b/src/applications/settings/panel/PhabricatorMultiFactorSettingsPanel.php index 492544bef6..b9d4beef4d 100644 --- a/src/applications/settings/panel/PhabricatorMultiFactorSettingsPanel.php +++ b/src/applications/settings/panel/PhabricatorMultiFactorSettingsPanel.php @@ -245,10 +245,18 @@ final class PhabricatorMultiFactorSettingsPanel $menu->addItem($item); } - return $this->newDialog() + $dialog = $this->newDialog() ->setTitle(pht('Choose Factor Type')) ->appendChild($menu) ->addCancelButton($cancel_uri); + + if ($viewer->getIsEnrolledInMultiFactor()) { + $dialog->appendRemarkup(pht( + 'NOTE: You already have an Auth Factor configured. Adding '. + 'another factor will require you to always provide all Auth '. + 'Factors instead of selecting one of your Auth Factors.')); + } + return $dialog; } // NOTE: Beyond providing guidance, this step is also providing a CSRF gate -- 2.51.2