From 3967d2a3b6ca2659267a0b72f5f77f4afb1f4b8b Mon Sep 17 00:00:00 2001 From: Ralf Becker Date: Fri, 6 Sep 2019 10:36:21 +0200 Subject: [PATCH] fix aborted WebAuthn not treated as failure of 2nd factor, if registered --- api/src/Session.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/api/src/Session.php b/api/src/Session.php index 064e2d40b8..5e30b6a1cb 100644 --- a/api/src/Session.php +++ b/api/src/Session.php @@ -795,7 +795,7 @@ class Session 'remember_me_token' => $token, ], [], true); - if (!count($factors) && (isset($errors['2fa_code']) || + if (!count($factors) && (count($errors) || $GLOBALS['egw_info']['server']['2fa_required'] === 'strict')) { if (!empty($code) && isset($errors['2fa_code']))