Skip to content

require TwoFA to be verified before updating code base #14251

@paulrudy

Description

@paulrudy

When visiting self-hosted Matomo installation (with two-factor authentication enabled):

  1. Matomo prompted for login/pass, but did not require 2 factor authentication
  2. Matomo prompted for upgrade
  3. I initiated upgrade and Matomo completed it
  4. An error page—referencing something like a loop. I didn't copy it, sorry.
  5. Browsed back
  6. Matomo showed upgrade successfully completed page
  7. Matomo finally asks for 2 factor authentication

It seems to me 2 factor authentication should be successfully completed before prompting for upgrade and before permitting initiation of upgrade.

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugFor errors / faults / flaws / inconsistencies etc.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions