Edit history

Earlier versions of Adding a passkey makes it mandatory as MFA on other devices, newest first.

Current version | Edited by Rex
Changes
Self-hosted, PostgreSQL 16, FLUXER_IMAGE_TAG=v1Removed: ### EvidenceRemoved: Removed: _No response_Removed: Removed: ### AcknowledgementsRemoved: Removed: - ☑ I searched open and closed issues.Removed: - ☑ I removed secrets and unrelated personal data from the report.Removed:
Show

Adding a passkey makes it mandatory as MFA on other devices

Observed behaviour

After adding a passkey on one PC, I tried to log in from a different PC using email + password. Fluxer then required the passkey as a second authentication factor. The passkey was stored on the first PC and was not available on the second one, so I was effectively unable to log in from the new device. TOTP/2FA was disabled. Simply adding a passkey caused Fluxer to start requiring WebAuthn after password authentication. A passkey should be an alternative login method, not automatically become a mandatory second factor for password logins. I should still be able to log in with email + password when TOTP/2FA is disabled, even if a passkey is registered on another device.

Reproduction steps

  1. On PC A, use an account with TOTP/2FA disabled.
  2. Add a passkey stored locally on PC A.
  3. On PC B, where that passkey is not available, open Fluxer.
  4. Log in using the same email and password.
  5. Fluxer requires the passkey as MFA.
  6. Login cannot be completed because the passkey only exists on PC A.

Build information

Canary Desktop 2026.811.124022, Stable Web 2026.812.122910, Windows 11 10.0.26200 (x64), Electron 41.2.2, Chrome 146.0.7680.188, Node 24.14.1, Locale fr

Affected surface

Web app, Desktop app

Instance

Self-hosted, PostgreSQL 16, FLUXER_IMAGE_TAG=v1
Original by Rex
Show

Adding a passkey makes it mandatory as MFA on other devices

Observed behaviour

After adding a passkey on one PC, I tried to log in from a different PC using email + password. Fluxer then required the passkey as a second authentication factor. The passkey was stored on the first PC and was not available on the second one, so I was effectively unable to log in from the new device. TOTP/2FA was disabled. Simply adding a passkey caused Fluxer to start requiring WebAuthn after password authentication. A passkey should be an alternative login method, not automatically become a mandatory second factor for password logins. I should still be able to log in with email + password when TOTP/2FA is disabled, even if a passkey is registered on another device.

Reproduction steps

  1. On PC A, use an account with TOTP/2FA disabled.
  2. Add a passkey stored locally on PC A.
  3. On PC B, where that passkey is not available, open Fluxer.
  4. Log in using the same email and password.
  5. Fluxer requires the passkey as MFA.
  6. Login cannot be completed because the passkey only exists on PC A.

Build information

Canary Desktop 2026.811.124022, Stable Web 2026.812.122910, Windows 11 10.0.26200 (x64), Electron 41.2.2, Chrome 146.0.7680.188, Node 24.14.1, Locale fr

Affected surface

Web app, Desktop app

Instance

Self-hosted, PostgreSQL 16, FLUXER_IMAGE_TAG=v1

Evidence

No response

Acknowledgements

  • ☑ I searched open and closed issues.
  • ☑ I removed secrets and unrelated personal data from the report.