I have 2FA configured on my PVE and PBS machines.
This issue exists in both PVE and PBS. I've recently noticed that when I accidentally entered the wrong password (typo), I did not get a 2FA prompt, just an error message.
Is this a bug or is this done on purpose ? If this is done on purpose, this is a bad design choice which weakens the second factor by revealing the fact that a correct password was entered. Second factor prompt should be shown at all times, regardless if the password is correct. Ideally, both password and 2FA should be validated together, not separately.
This issue exists in both PVE and PBS. I've recently noticed that when I accidentally entered the wrong password (typo), I did not get a 2FA prompt, just an error message.
Is this a bug or is this done on purpose ? If this is done on purpose, this is a bad design choice which weakens the second factor by revealing the fact that a correct password was entered. Second factor prompt should be shown at all times, regardless if the password is correct. Ideally, both password and 2FA should be validated together, not separately.