a next session, the user disables 2FA, later re-enables it (the tokens have changed)
Each login would be new token sent. I sign in to by doctor all the time with 2fa, I get sent a code on cell phone to enter.
Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.
Hi, I integrated Fortify in my application with two-factor authentication.
I managed to create a profile page with a dropdown to enable and disable 2FA. Say we have the following situation:
So, the user cannot login anymore. A solution would be that te user can e-mail a 2FA-code to login. But I have no idea if this is possible to implement.
Maybe there is another workaround for this. Anyone any idea?
Please or to participate in this conversation.