bzcomputers
Well-known member
While testing out two-step verification (on accident), I found that disabling two-step verification within the usergroup permissions does not appear to disable it for the existing users within that usergroup.
My Scenario:
I accidentally turned on two-step verification for Administrators. I attempted to login and found that it was turned on, so I went back into permissions and turned it off for Administrators. Only it did not disable it for existing users. It disabled it for any new administrator created but for existing administrators they had to manually go into there own profile under "Password and security" and disable it there also.
My Question:
If I accidentally turn on two-step verification for registered users and then immediately turn it off will each registered users still need to manually go in under their own profiles and also disable two-step verification there? If this is true and unintended please move into bug reports. If this is true and intended, I can see this being a huge headache for admins for a simple mistake of one click and save. I can only imagine the the mass of emails and complaints coming in from registered users or any other group you make the mistake on.
Suggestion:
If it is true and intended, I think this could be handled better by XenForo. I couldn't find the table where this info is stored to see how it is currently done, but how about saving both a manual two-step verification (on/off) and a group permission two-step verification (on/off). Then if a usergroup is no longer required to have two-step verification it will default back to what the user originally had prior to being forced by usergroup permission into a two-step verification. Those who didn't have two-step verification manually turned on prior to their usergroup enforcing it will then automatically go back to it being disabled without any manual profile changes needed. Those who had it turned on prior to their usergroup enforcing it will just see no change, it will continue to work as before.
My Scenario:
I accidentally turned on two-step verification for Administrators. I attempted to login and found that it was turned on, so I went back into permissions and turned it off for Administrators. Only it did not disable it for existing users. It disabled it for any new administrator created but for existing administrators they had to manually go into there own profile under "Password and security" and disable it there also.
My Question:
If I accidentally turn on two-step verification for registered users and then immediately turn it off will each registered users still need to manually go in under their own profiles and also disable two-step verification there? If this is true and unintended please move into bug reports. If this is true and intended, I can see this being a huge headache for admins for a simple mistake of one click and save. I can only imagine the the mass of emails and complaints coming in from registered users or any other group you make the mistake on.
Suggestion:
If it is true and intended, I think this could be handled better by XenForo. I couldn't find the table where this info is stored to see how it is currently done, but how about saving both a manual two-step verification (on/off) and a group permission two-step verification (on/off). Then if a usergroup is no longer required to have two-step verification it will default back to what the user originally had prior to being forced by usergroup permission into a two-step verification. Those who didn't have two-step verification manually turned on prior to their usergroup enforcing it will then automatically go back to it being disabled without any manual profile changes needed. Those who had it turned on prior to their usergroup enforcing it will just see no change, it will continue to work as before.
Upvote
0