<feed xmlns='http://www.w3.org/2005/Atom'>
<title>cccms/test/controllers/otp_challenges_controller_test.rb, branch master</title>
<subtitle>[no description]</subtitle>
<id>http://erdgeist.org/gitweb/cccms/atom?h=master</id>
<link rel='self' href='http://erdgeist.org/gitweb/cccms/atom?h=master'/>
<link rel='alternate' type='text/html' href='http://erdgeist.org/gitweb/cccms/'/>
<updated>2026-07-24T11:53:13Z</updated>
<entry>
<title>Complete the login only after the second factor</title>
<updated>2026-07-24T11:53:13Z</updated>
<author>
<name>erdgeist</name>
<email>erdgeist@erdgeist.org</email>
</author>
<published>2026-07-24T11:53:13Z</published>
<link rel='alternate' type='text/html' href='http://erdgeist.org/gitweb/cccms/commit/?id=dcb576618b868b888a5b1b31e35491f300ce4050'/>
<id>urn:sha1:dcb576618b868b888a5b1b31e35491f300ce4050</id>
<content type='text'>
Enrolled users get a pending marker instead of a session after the
password step; a valid code through the challenge writes the real
session via reset_session. otp_required without enrollment funnels
into setup everywhere except the enrollment, user, and login
machinery.
</content>
</entry>
</feed>
