Skip to content

Deeplink-2FA code is requested for users without 2FA enabled when signing in via public room. #100433

Description

@applause-bot

If you haven’t already, check out our contributing guidelines for onboarding. To join our Slack channel, fill out this form.


Version Number: v9.4.72-2
Reproducible in staging?: Yes
Reproducible in production?: No
If this was caught during regression testing, add the test name, ID and link from BrowserStack: https://test-management.browserstack.com/projects/2219752/folder/13176964/test-cases/41237765
Email or phone of affected tester (no customers): htad26+@gmail.com
Issue reported by: Applause Internal Team
Bug source: Regression TC Execution
Device used: Windows 10 / Chrome
App Component: Other

Action Performed:

  1. Log out of New Expensify
  2. Navigate to a public room link - (you can use this one https://staging.new.expensify.com/r/1540486774487195)
  3. Click on Sign In
  4. Log in with an existing account that doesn't have 2FA set up
  5. Enter magic code

Expected Result:

The user is signed in

Actual Result:

2FA recovery code is requested even if the user hasn't set up 2FA in their account

Workaround:

Unknown

Platforms:

  • Android: App
  • Android: mWeb Chrome
  • iOS: App
  • iOS: mWeb Safari
  • iOS: mWeb Chrome
  • Windows: Chrome
  • MacOS: Chrome Safari

Screenshots/Videos

Bug7251482_1788550736460.bandicam_2026-09-04_22-36-54-604.mp4

View all open jobs on GitHub

Applause Internal Information
Exported by: Svetlana Lazutkina
Bug ID: 7251482

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

BugSomething is broken. Auto assigns a BugZero manager.DeployBlockerIndicates it should block deploying the APIEngineeringHourlyKSv2ReviewingHas a PR in review

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions