Guard the TOTP verifyKey call behind hasTotp() so a key-only user's null two_factor_secret never reaches Google2FA::verifyKey(); they reset via a backup code. Also adds the reset_no_2fa_note lang key (EN + DE) rendered on the forgot-password form explaining the no-2FA recovery options. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| .gitkeep | ||
| ForgotPassword.php | ||
| Login.php | ||
| PasswordChange.php | ||
| ResetPassword.php | ||
| TwoFactorChallenge.php | ||
| TwoFactorSetup.php | ||