If you haven’t already, check out our contributing guidelines for onboarding. To join our Slack channel, fill out this form.
Version Number: Not specified in the follow-up report.
Reproducible in staging?: Needs confirmation.
Reproducible in production?: Reported from customer setup attempts; not independently reproduced for this issue.
If this was caught during regression testing, add the test name, ID and link from BrowserStack: Not provided.
Email or phone of affected tester (no customers): Not provided.
Logs: The source report summarizes a September 10 Toggle/Validate failure loop; see Additional Context.
Expensify/Expensify Issue URL: Not specified in the source comment.
Issue reported by: @neerajbachani and team.
Slack conversation (hyperlinked to channel name): Not provided for this case.
Action Performed:
Precondition: The user is setting up 2FA and has not completed validation.
- Start 2FA setup.
- Scan the displayed QR code into an authenticator app.
- Exit the setup page before completing setup.
- Reopen the setup page.
- Enter a current code from the authenticator entry created in step 2.
Expected Result:
Returning to an in-progress setup preserves its secret. Codes generated from the QR code already scanned remain valid, allowing the user to finish setup.
Actual Result:
The app repeatedly displays Invalid code. Reopening or refocusing the codes page can issue another Toggle request, generating a different server-side secret while the authenticator still uses the previously scanned one.
Workaround:
No confirmed workaround is documented for this specific case in the source report.
Additional Context:
Split from problem 3 in the follow-up report on #91985.
The report describes this September 10 sequence:
Toggle(200) → Validate(401) ×6 → Toggle(200, NEW secret) → Validate(401) → Toggle(200)
The reported trigger is DynamicTwoFactorAuthPage.tsx, which calls Toggle when the page opens or receives focus without codes in storage. Suggested fix: initialize once per setup and reuse the in-progress secret when returning to that setup.
Regression coverage should verify successful validation after leaving/reopening or refocusing an unfinished setup, no unintended repeated Toggle requests, and correct initialization for a genuinely new setup.
Platforms:
The follow-up report does not specify the exact reproduced platforms.
Screenshots/Videos
None attached to this case in the source report.
View all open jobs on GitHub
Upwork Automation - Do Not Edit
Issue Owner
Current Issue Owner: @neerajbachani
If you haven’t already, check out our contributing guidelines for onboarding. To join our Slack channel, fill out this form.
Version Number: Not specified in the follow-up report.
Reproducible in staging?: Needs confirmation.
Reproducible in production?: Reported from customer setup attempts; not independently reproduced for this issue.
If this was caught during regression testing, add the test name, ID and link from BrowserStack: Not provided.
Email or phone of affected tester (no customers): Not provided.
Logs: The source report summarizes a September 10 Toggle/Validate failure loop; see Additional Context.
Expensify/Expensify Issue URL: Not specified in the source comment.
Issue reported by: @neerajbachani and team.
Slack conversation (hyperlinked to channel name): Not provided for this case.
Action Performed:
Precondition: The user is setting up 2FA and has not completed validation.
Expected Result:
Returning to an in-progress setup preserves its secret. Codes generated from the QR code already scanned remain valid, allowing the user to finish setup.
Actual Result:
The app repeatedly displays Invalid code. Reopening or refocusing the codes page can issue another Toggle request, generating a different server-side secret while the authenticator still uses the previously scanned one.
Workaround:
No confirmed workaround is documented for this specific case in the source report.
Additional Context:
Split from problem 3 in the follow-up report on #91985.
The report describes this September 10 sequence:
The reported trigger is DynamicTwoFactorAuthPage.tsx, which calls Toggle when the page opens or receives focus without codes in storage. Suggested fix: initialize once per setup and reuse the in-progress secret when returning to that setup.
Regression coverage should verify successful validation after leaving/reopening or refocusing an unfinished setup, no unintended repeated Toggle requests, and correct initialization for a genuinely new setup.
Platforms:
The follow-up report does not specify the exact reproduced platforms.
Screenshots/Videos
None attached to this case in the source report.
View all open jobs on GitHub
Upwork Automation - Do Not Edit
Issue Owner
Current Issue Owner: @neerajbachani