Skip to content

Conversation

@MKodde
Copy link
Member

@MKodde MKodde commented Dec 30, 2025

Created a form to remove the recovery token.

On this form, the user is warned about the removal and is asked for confirmation.

The texts are translated according to the regular 2fa token removal form so the tone of voice should match. But PO might want to sharpen these translations.

A test for this feature will be was added to the Behat test suite in stepup devconf

OpenConext/OpenConext-devconf#68

@MKodde MKodde linked an issue Dec 30, 2025 that may be closed by this pull request
@MKodde MKodde force-pushed the 425-csrf-on-token-deletion-endpoint-missing branch from d7bafcc to 5065948 Compare January 6, 2026 09:10
MKodde added 2 commits January 6, 2026 10:14
Works,
- needs translation token attention
- warn about new translations
- Show ID of safe-store RT?
- test coverage?
@MKodde MKodde force-pushed the 425-csrf-on-token-deletion-endpoint-missing branch from 5065948 to 9968991 Compare January 6, 2026 09:14
@MKodde MKodde requested a review from johanib January 6, 2026 09:15
@MKodde MKodde changed the title WIP: Transform RT delete into SF form Transform RT delete into SF form Jan 6, 2026
@MKodde MKodde force-pushed the 425-csrf-on-token-deletion-endpoint-missing branch from 3417a3f to 7043328 Compare January 6, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CSRF on token deletion endpoint missing

3 participants