Closed Bug 1470335 Opened 6 years ago Closed 6 years ago

Can't disable Two Step Authentication

Categories

(Cloud Services :: Server: Firefox Accounts, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED INACTIVE

People

(Reporter: bensaltz, Unassigned)

Details

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:60.0) Gecko/20100101 Firefox/60.0
Build ID: 20180605171542

Steps to reproduce:

1. Open menu and click on my user (Opens Firefox Sync setting page for my user)
2. Click disable on Two Step Authentication


Actual results:

Nothing happens and Javascript Console shows the error "Error: Unverified session".
I have tried reloading the page and using a private window.


Expected results:

Two Step Authentication is disabled
Component: General → Firefox Sync: Backend
Thanks for the report!  Just to confirm, are you are accessing this page from a signed-in Firefox browser, by clicking through the "manage account" link in the Firefox Sync settings page?  Did go straight to displaying the account settings, or did it prompt you to re-enter your password?
Component: Firefox Sync: Backend → Server: Firefox Accounts
Flags: needinfo?(bensaltz)
> I have tried reloading the page and using a private window.

As a workaround, if you use a private window and visit https://accounts.firefox.com/settings directly (rather than through browser settigs) then it should prompt you to sign in again, and should produce a correctly verified session that can disable two-step authentication.
I have seen a similar problem where to enable TOTP a verified session is needed, I'm trying to find the issue. I imagine this is the opposite, the user has a session from before TOTP was added. Since TOTP is enabled, they are able to open the TOTP settings panel. They try to disable. Wah wah.
Hey bensaltz, are you still experiencing issues removing Two Step Authentication?
Status: UNCONFIRMED → RESOLVED
Closed: 6 years ago
Resolution: --- → INACTIVE

I have exactly the same problem. I just realized it because I factory reseted my phone with my two-factor auth app so I can't log in from a private window.
My account is still connected on my windows PC but can't disable 2FA. Same Error: Unverified session.

Flags: needinfo?(bensaltz)
You need to log in before you can comment on or make changes to this bug.