docs: document backup codes for users who sign in with password + TOTP #167
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web#167
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Why
"I lost my authenticator app" currently has no self-service answer for a password + TOTP user
beyond a full credential reset. The identity provider has supported backup codes for exactly
this case for a long time — the release notes describe "backup codes as MFA in case of lost
TOTP/Webauthn" — and they are generated inside the ordinary credential-update flow, so they are
available to our users today. No server change is needed.
They are undocumented on our side, and the upstream "Authentication and Credentials" page does not
mention them either, so in practice nobody knows they exist.
This is the cheap half of the lost-authenticator problem. It is also the pattern that already
rescued the second-factor lockout in gitborg/gitborg-infra#292 on the git-host side: recovery codes are stored hashed
rather than encrypted, so they survive events that destroy the enrolled secret.
Scope
and how to use one to sign in.
password path.
Done when
A user who signs in with password + TOTP can find, in our own docs, how to get back in after losing
their phone — without contacting the operator.
Part of gitborg/gitborg-docs#69.
supernaut refererade till detta ärende från bitborg/bitborg-docs2026-08-02 12:32:47 +00:00