Observed behaviour
After adding a passkey on one PC, I tried to log in from a different PC using email + password.
Fluxer then required the passkey as a second authentication factor.
The passkey was stored on the first PC and was not available on the second one, so I was effectively unable to log in from the new device.
TOTP/2FA was disabled. Simply adding a passkey caused Fluxer to start requiring WebAuthn after password authentication.
A passkey should be an alternative login method, not automatically become a mandatory second factor for password logins.
I should still be able to log in with email + password when TOTP/2FA is disabled, even if a passkey is registered on another device.
Reproduction steps
- On PC A, use an account with TOTP/2FA disabled.
- Add a passkey stored locally on PC A.
- On PC B, where that passkey is not available, open Fluxer.
- Log in using the same email and password.
- Fluxer requires the passkey as MFA.
- Login cannot be completed because the passkey only exists on PC A.
Canary Desktop 2026.811.124022, Stable Web 2026.812.122910, Windows 11 10.0.26200 (x64), Electron 41.2.2, Chrome 146.0.7680.188, Node 24.14.1, Locale fr
Affected surface
Web app, Desktop app
Instance
Self-hosted, PostgreSQL 16, FLUXER_IMAGE_TAG=v1
10 comments
Comment by Hampus
Comment by @Victor-root
- PC A: account has a locally stored passkey
- PC B: that passkey is not available
- TOTP is disabled
- I enter the correct email and password on PC B
- Fluxer then requires the passkey from PC A, so I cannot log in at all
So this is not just about convenience. Registering a device-bound passkey on one machine can make the account inaccessible from another machine unless the user has already configured another MFA method.Comment by Hampus
Comment by @Victor-root
Comment by @Artimba
Comment by @Septicity
Comment by @nwenny
Comment by Hampus
Comment by Hampus
Comment by Hampus