This is not a bug report but is a feature request to potentially allow instances to configure whether WebAuthn is a two-factor authentication method or not. Fluxer has made the decision, like Discord, that WebAuthn is a two-factor authentication method, and it is implemented as such. If it weren't required to login to your account, but you could just use an email and password, it is not two-factor authentication and it provides zero extra security. It only provides convenience. That may be a valid way someone wants their instance to work, however, and it is worth discussing as a feature request.
RexSystem1 voteoriginally by @Victor-root on GitHub OP
I understand that WebAuthn is intentionally treated as MFA.
The problem I'm pointing out is that this can completely block login on another device if the registered passkey is device-bound.
Example:
PC A: account has a locally stored passkey
PC B: that passkey is not available
TOTP is disabled
I enter the correct email and password on PC B
Fluxer then requires the passkey from PC A, so I cannot log in at all
So this is not just about convenience. Registering a device-bound passkey on one machine can make the account inaccessible from another machine unless the user has already configured another MFA method.
I believe you should have been offered the option to download backup codes when setting up WebAuthn as an MFA method. When you cannot access a specific MFA method, it is intentional that you cannot login to your account, since you do not have access to the MFA method in question. Otherwise it is not MFA. But with backup codes, you should be able to sign in to your account anyway. Let me know if this is not working as you expect, however, but this would be the solution to your problem at this time, aside from not using device-bound passkeys. Passkeys generally are a very poor UX and I wouldn't recommend them to most people. I'm open to practical suggestions, however.
RexSystem1 voteoriginally by @Victor-root on GitHub OP
I think we're talking past each other, my issue is not about recovery or backup codes.
I did NOT enable two-factor authentication. I only added a passkey as an authentication method.
Registering a passkey should not implicitly opt me into mandatory password + WebAuthn MFA unless I explicitly choose to enable that.
A passkey can be used as a primary authentication method; registering one does not inherently mean the user wants it enforced as a second factor for password logins.
The lockout on my second PC is just the consequence of that unexpected behaviour.
I get the confusion here. I am an avid passkey user (between a yubikey and bitwarden), and see why having 2FA disabled would lead to the belief that the passkey is just an alt auth method. Bitwarden passkey's offer a convenience to many platforms, while my yubikey is a security device. With more password managers adding support for them, I see this becoming a more common frustration.
The ability to add a passkey while 2FA is disabled is strange if the intended behavior is that passkeys MUST be 2FA. I would imagine adding a passkey immediately toggles on 2FA and disables the button in that case (or pops up a modal warning the user about the passkey when trying to disable 2FA with one).
Also its sad hearing that passkeys are considered bad UX. I thought they were one of the greatest things to happen with password managers.
Thread
Comment by Hampus
Comment by @Victor-root
- PC A: account has a locally stored passkey
- PC B: that passkey is not available
- TOTP is disabled
- I enter the correct email and password on PC B
- Fluxer then requires the passkey from PC A, so I cannot log in at all
So this is not just about convenience. Registering a device-bound passkey on one machine can make the account inaccessible from another machine unless the user has already configured another MFA method.Comment by Hampus
Comment by @Victor-root
Comment by @Artimba