TOTP 2FA only works with email link

I setup the TOTP authenticator (KeePassXC) as usual and all seemed, as usual, fine.

However it’s failing 100% of the time since, when I try to login in the normal way – user + pw + totp code

The only thing I can see is the normal login approach, the discourse automatically add an and initiates the login process without me needing to click blue [log in] button.

wash, rinse, repeat..

If however I restart the process from the beginning, and use the ‘skip password and get an e-mail’ option, the link provided which then asks for the TOTP code accepts the code and -waits- for me to click [ Log in ] … and works as expected.

The only possible cause I suspect is clock drift on the server. We’ll have to check.

Thanks for the heads up!

Hmm, the date seems correct on our server.

You know, I had an issue like this on other sites once, like multiple sites including my credit card/bank, and some other major accounts. I thought my password manager 1Password was trippin’. But it turns out my PC clock was wrong.

Hi Matt,

I appreciate the response.

My clock is in sync using 3 nist pools and ticks in ~perfect sync with time.gov

I’ve no trouble with 2FA login to the discourse used at https://discuss.linuxcontainers.org/ ..I think that’s the only other discourse login I have to compare with.

I will enable it again here and see how it goes. It’s odd that the OTP worked fine by the email link both times, and 0/2 on the normal OTP login.

Same outcome.

I setup the TOTP 2FA (fwiw: manual code reveal to seed the authenticator), generated the backup codes and logged out.

I manually input the auth code (vs KeePassXC browser plug-in filling) and ‘please wait before trying to log in again’ – fyi, same outcome using the browser plug-in to provide the code or manually input.

This time I just used one of the backup codes to login.

The only other thing I can think of is that the failure is instant. I see no login spinner on the [ Log In ] button as I see when login to the other discourse I use.

..on the secret key input (setting up the TOTP) I’m going with the default (RFC 6238) settings which seem to be always correct for the multitude of sites I use 2FA.

It’s the login rate limiting. If you wait a minute then supply the TOTP code then it works.

Unless it’s considering the time I presented the name + pw creds it’s rate limiting against what?

..the 1st code entry prompt I see is failing. I tried it several times after discovering the failure, of no specific cadence, but I did attempt to account for some rate limiting by waiting.. I don’t recall the max I waited before trying again, but I probably waited ~minute, maybe longer.

I’ll give it a try again and see how it deals with an ample amount of time delay after the initial instant failure.

It’s exactly that. After you’ve entered your name/password, you can’t submit to the same endpoint (which is where the TOTP goes too) for a minute. So just wait at least a minute, make sure you submit an updated TOTP code though.

Sorry about the aggressive rate limiting. We had a bad case of scammers/spammers hitting the forum, and the rate limiting helped slow it down to manageable volume.

Ah… I see!

I did read about the spam invasion while browsing through the topics. Good riddance and worth the pause to before 2FA if it’s helped keep the varmints out.

I guess a majority of visitors use alternate logins like google, etc or no 2FA.. or I missed the PSA :upside_down_face: Got one now! :grin: