packagist
packagist copied to clipboard
2FA requirement when using "password forgotten"
I needed to use the "forgot password" feature on a company account because the original maintainer wasn't working for this company, the reset link was mailed and I could change the password. However after login I got the 2FA request and needed to contact the original maintainer of this account to disable the 2FA. He stated that the password was indeed changed and I had to provide him the original password.
Change requested: Ask for 2FA before storing the new password if 2FA is enabled.