Skip to content

2FA Ask for password not username when disabling 2FA #5825

@jezdez

Description

@jezdez

Describe the bug
When disabling 2FA for an account, it would make sense to ask for the user's password and not the username for confirmation as that would make it much harder to do drive-by disabling on unattended computers.

Expected behavior

Ask for password when disabling 2FA.

To Reproduce

Try disabling 2FA on https://pypi.org/manage/account/.

Metadata

Metadata

Labels

UX/UIdesign, user experience, user interfacefeature requestneeds discussiona product management/policy issue maintainers and users should discuss

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions