Bug Login via Passkey sets remember but not tfa_trust cookie

There is a bug in this version
K

Kirby

Guest
When logging in with a Passkey, XenForo automatically sets cookie _user so th user stays "logged in" but it does not set cookie tfa_trust so for the next session a TFA verification is required - which can be performed with the same Passkey that was used to initially log in.

IMHO this doesn't make much sense and probably annoys & confuses users.

XenForo should either
  1. Always set user and tfa_trust cookies when logging in via Passkey
    Preferred
  2. Never...

Read more

Continue reading...