Project

General

Profile

Actions

Bug #99864

closed

Notify by email on login not working after user activates MFA

Added by J. Peter M. Schuler almost 2 years ago. Updated 5 months ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
Authentication
Target version:
-
Start date:
2023-02-07
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
11
PHP Version:
7.4
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

There is a backend user setting “notify by email on login” which is considered “personal tab” not “account security”.
This works fine, unless the user activates MFA/OTP. Then, no matter if the notify option is set or not, no mail is sent on login.

IMHO this is no security problem, however that is not for me to consider, thus better be safe and post this as a private issue.


Related issues 3 (0 open3 closed)

Related to TYPO3 Core - Bug #100128: AdminLoginWarning email not sent when MFA is activated Closed2023-03-09

Actions
Related to TYPO3 Core - Bug #100129: Hook "postLoginFailureProcessing" is not called when MFA TOTP verification failed Closed2023-03-09

Actions
Related to TYPO3 Core - Bug #104809: Exception in BE login notification with f:translate in custom SystemEmail layoutClosedMathias Brodala2024-09-04

Actions
Actions #1

Updated by J. Peter M. Schuler almost 2 years ago

  • Description updated (diff)
Actions #2

Updated by Oliver Hader almost 2 years ago

Seems to be a bug then. This is not considered a vulnerability, since it has no impact on confidentiality, integrity or availability.

Actions #3

Updated by Oliver Hader almost 2 years ago

  • Private changed from Yes to No
Actions #4

Updated by Oliver Hader almost 2 years ago

I made this issue public.

Actions #5

Updated by RVVN no-lastname-given over 1 year ago

  • Related to Bug #100128: AdminLoginWarning email not sent when MFA is activated added
Actions #6

Updated by Benni Mack over 1 year ago

  • Related to Bug #100129: Hook "postLoginFailureProcessing" is not called when MFA TOTP verification failed added
Actions #7

Updated by Gerrit Code Review over 1 year ago

  • Status changed from New to Under Review

Patch set 1 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/79805

Actions #8

Updated by Oliver Bartsch over 1 year ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100
Actions #9

Updated by Gerrit Code Review over 1 year ago

  • Status changed from Resolved to Under Review

Patch set 1 for branch 12.4 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/79807

Actions #10

Updated by Oliver Bartsch over 1 year ago

  • Status changed from Under Review to Resolved
Actions #11

Updated by Benni Mack 5 months ago

  • Status changed from Resolved to Closed
Actions #12

Updated by Stefan Bürk 3 months ago

  • Related to Bug #104809: Exception in BE login notification with f:translate in custom SystemEmail layout added
Actions

Also available in: Atom PDF