Reply to thread

Not reproducible for me.


Steps I've taken

  1. Logged out of xenforo.com in desktop chrome
  2. Cleared all cookies for xenforo.com in desktop chrome
  3. Logged in with my YubiKey 5 in desktop chrome
  4. Unplugged YubiKey from USB but kept desktop chrome session open
  5. Plugged YubiKey into USB on my notebook
  6. Logged into xenforo.com with the YubiKey in notebook chrome
  7. Checked status of desktop chrome session

Result

I was still logged into xenforo.com in desktop chrome


But there is an issue regarding Passkey login:

When logging into an account with Stay logged in ticked using a passkey on a fresh browser XenForo does not set cookie xf_tfa_trust.

So when the session expires or becomes otherwise invalid TFA will be required.


This is not technically "wrong" (passkey login does not ask wether to trust the device) but kinda unexpected.

Passkey login therefor should probably set that cookie if Stay logged in is ticked.


Back
Top Bottom