trudesk icon indicating copy to clipboard operation
trudesk copied to clipboard

Bypass of 2FA when using mobile version

Open eboss-dev opened this issue 2 years ago • 3 comments

Is this a BUG REPORT or FEATURE REQUEST?:

  • [x] BUG
  • [ ] FEATURE

What happened: I tried setting up the 2FA with Duo. It works fine as long as I use the desktop version. When I switch to the mobile one the 2FA is completely by-passed

What did you expect to happen: 2FA working in the mobile version too

How to reproduce it (as minimally and precisely as possible): I try to reproduce using a phone without the authenticator as well as in chrome with the inspection tool emulating a phone. When I am at this path (yourTrudeskURL/mobile/#/login) I don't get the request for a code.

Anything else we need to know?:

Environment:

  • Trudesk Version: 1.0
  • OS (e.g. from /etc/os-release): Ubuntu 22.04 LTS
  • Node.JS Version: 10.10 Alpine
  • MongoDB Version: Mongo 3.6
  • Is this hosted on cloud.trudesk.io: no

eboss-dev avatar Sep 18 '23 15:09 eboss-dev

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

github-actions[bot] avatar Oct 18 '23 21:10 github-actions[bot]

The mobile view is being rewritten. It currently uses an outdated view of ionic and is completely broken. Mobile view will be disabled in an upcoming release while the rewrite occurs.

polonel avatar Oct 31 '23 04:10 polonel