Cannot change member verification level without enabling 2FA, even when 2FA requirement is disabled

(#130) Bug Confirmed moderation security

Summary

When editing a community’s Safety & Moderation settings and changing the member verification level from None to Low or Medium, Fluxer incorrectly blocks the change and requires 2FA to be enabled on the account, even though 2FA is not required in the community settings. Expected Behavior: The verification level should be updated successfully, since the community does not require moderators to have 2FA enabled.

Steps to reproduce

Create a new community. Dont have 2FA enabled on your account (by default) Open the community settings. Navigate to Safety & Moderation. Change Member Verification Level from None to Low or Medium. Click Save. Enter account password when prompted. Observe error message.

Environment (optional)

NOT SELF HOSTED Client: Fluxer Desktop App Client Channel: Stable Client Version: stable (d90628a) Desktop App Version: 0.0.8 Build Timestamp: 2026-02-16 10:10:38 UTC Electron Version: 39.2.7 Operating System: Windows 11 10.0.26100 (x64) Install Method: Official Fluxer desktop installer Account Type: Community Owner / Administrator 2FA Status: Disabled on account Reproducibility: 100% (occurs every time when changing verification level from None to Low/Medium and saving) Workaround: None (must enable 2FA to proceed, which should not be required)

Logs or screenshots (optional)

image image
  • 550581173-57fc5d2a-b412-4319-812f-5a4bed666fb8.png

    550581173-57fc5d2a-b412-4319-812f-5a4bed666fb8.png

    441×304 | 19 kB

  • 550581345-3fabe23c-1c45-4c06-984d-c398dd86546a.png

    550581345-3fabe23c-1c45-4c06-984d-c398dd86546a.png

    713×188 | 17 kB

2 comments

Sign in with Fluxer to comment and vote.
Comment by Rex
RexSystem 1 vote
Status changed from Fixed to Confirmed
Reopened because another user confirmed the server rejects the change and it was bulk closed without a fix.
Comment by @automataevox
RexSystem 1 vote originally by @automataevox on GitHub
PATCH https://web.fluxer.app/api/v1/guilds/%3Cguild-id/%3E 400 Bad Request
// request

{
    "verification_level": 1,
    "nsfw_level": 0,
    "explicit_content_filter": 1,
    "mfa_level": 0,
    "password": "REDACTED"
}
// response

{
  "code": "INVALID_FORM_BODY",
  "message": "Invalid form body.",
  "errors": [
    {
      "path": "mfa_level",
      "message": "You must enable 2FA on your account before requiring it for moderators.",
      "code": "MUST_ENABLE_2FA_BEFORE_REQUIRING_FOR_MODS"
    }
  ]
}
In request MFA is not enabled, so it's server-side validation failure