Skip to content

2FA - Reopening setup regenerates the secret and invalidates authenticator codes #102575

Description

@luacmartins

If you haven’t already, check out our contributing guidelines for onboarding. To join our Slack channel, fill out this form.


Version Number: Not specified in the follow-up report.
Reproducible in staging?: Needs confirmation.
Reproducible in production?: Reported from customer setup attempts; not independently reproduced for this issue.
If this was caught during regression testing, add the test name, ID and link from BrowserStack: Not provided.
Email or phone of affected tester (no customers): Not provided.
Logs: The source report summarizes a September 10 Toggle/Validate failure loop; see Additional Context.
Expensify/Expensify Issue URL: Not specified in the source comment.
Issue reported by: @neerajbachani and team.
Slack conversation (hyperlinked to channel name): Not provided for this case.

Action Performed:

Precondition: The user is setting up 2FA and has not completed validation.

  1. Start 2FA setup.
  2. Scan the displayed QR code into an authenticator app.
  3. Exit the setup page before completing setup.
  4. Reopen the setup page.
  5. Enter a current code from the authenticator entry created in step 2.

Expected Result:

Returning to an in-progress setup preserves its secret. Codes generated from the QR code already scanned remain valid, allowing the user to finish setup.

Actual Result:

The app repeatedly displays Invalid code. Reopening or refocusing the codes page can issue another Toggle request, generating a different server-side secret while the authenticator still uses the previously scanned one.

Workaround:

No confirmed workaround is documented for this specific case in the source report.

Additional Context:

Split from problem 3 in the follow-up report on #91985.

The report describes this September 10 sequence:

Toggle(200) → Validate(401) ×6 → Toggle(200, NEW secret) → Validate(401) → Toggle(200)

The reported trigger is DynamicTwoFactorAuthPage.tsx, which calls Toggle when the page opens or receives focus without codes in storage. Suggested fix: initialize once per setup and reuse the in-progress secret when returning to that setup.

Regression coverage should verify successful validation after leaving/reopening or refocusing an unfinished setup, no unintended repeated Toggle requests, and correct initialization for a genuinely new setup.

Platforms:

The follow-up report does not specify the exact reproduced platforms.

  • Android: App
  • Android: mWeb Chrome
  • iOS: App
  • iOS: mWeb Safari
  • iOS: mWeb Chrome
  • Windows: Chrome
  • MacOS: Chrome / Safari

Screenshots/Videos

None attached to this case in the source report.

View all open jobs on GitHub

Upwork Automation - Do Not Edit
Issue OwnerCurrent Issue Owner: @neerajbachani

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

BugSomething is broken. Auto assigns a BugZero manager.DailyKSv2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions