New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Two factor authentication is broken #16396
Comments
|
I think I've found the problem here; commit 24c67f4 introduces a A proper fix will have to address both of these scenarios, but until we release 5.1.0 I believe we can simply comment out these lines, since warming the cache shouldn't affect 4.9 or 5.0. |
|
I am uploading new phpMyAdmin releases 4.9.7 and 5.0.4 which should fix this. Thank you for your report. |
|
but why do you starting with 5.0.4 you need now "vendor/pragmarx" to be present or you geta error about missing include in the src directory in case you never needed and wanted 2FA smart people remove everything which they don't use especially when software becomes more and more bloatet all the time one can't attack components which are phyiscally not present in case of a zero-day in teh future |
|
@thelounge-zz I believe I have reproduced this successfully, but want to make sure that I understand the steps you're taking.
With 5.0.2, when you run phpMyAdmin it would be fine, but starting with 5.0.4, you now get several notices at the bottom of the main window about ClassLoader not being able to find the pragmarx files. Is that correct? Can you click the "Ignore" or "Ignore All" buttons on the popup? This temporarily dismisses the warning for me, but it's back the next time I log in. |
|
well, i remember times where even fatures like export formats wheren't displayed when the files where not present |
This is quite strange because on Debian packaging I do not have any 2FA, U2F stuff. See #16362. And no error pops out 🤔 |
|
well, it would be nice to have a "basics" tarball without as much as possible 3rd party stuff not present at all instead the "rm -rf" orgy in phpMyAdmin.spec to begin with |
I agree, posted in #16418 |
|
@thelounge-zz Are there any other folders you remove that aren't listed in FAQ 1.44? We can add more to the lists there if there are some other folders that don't break phpMyAdmin. Also, I opened issue #16419 to directly address the pragmarx errors. |
|
rm -f rm -rf |
With the release of 4.9.6 and 5.0.3, two factor authentication is not available.
The error message is
This was first reported to me by Evert Jan van Ramselaar, who adds that "The file bundles for 5.0.3 do not contain the 'vendor/pragmarx' dependencies, where the file bundles for 5.0.2 did contain these."
Note that two factor authentication still seems to work correctly on master.
The text was updated successfully, but these errors were encountered: