Skip to content

2fa/MFA code invalid #6053

@msrv

Description

@msrv

Describe the Bug

Hi all,
I might have discovered a bug in v25.12.8

I am unable to enable the multi factor authentication. The qr code is displayed correctly & i can generate a one time code with my totp app (1password). However, the code is "invalid" and does not work.

Timezone settings on the server and my computer are the same.

Error log does not log any errors even if set to APP_DEBUG=true

I would be glad if anyone could help :) thank you!

Steps to Reproduce

  1. enable 2fa
  2. scan qr / enter totp secret
  3. enter the generated code
  4. code is invalid

Expected Behaviour

code should be valid

Screenshots or Additional Context

i run bookstack on ubuntu 24.04.4 LTS, Apache 2.4.58, PHP 8.3.6

Browser Details

No response

Exact BookStack Version

BookStack v25.12.8

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions