DEV: update rake task to disable 2FA for a user

- limits security key deletes to second factor keys
- also deletes backup codes (lingering backup codes break login flow entirely)
This commit is contained in:
Penar Musaraj 2024-10-02 09:43:12 -04:00
parent 3eada7b572
commit 426d677243
No known key found for this signature in database
GPG Key ID: E390435D881FF0F7
1 changed files with 7 additions and 1 deletions

View File

@ -155,7 +155,13 @@ task "users:disable_2fa", [:username] => [:environment] do |_, args|
username = args[:username]
user = find_user(username)
UserSecondFactor.where(user_id: user.id, method: UserSecondFactor.methods[:totp]).each(&:destroy!)
UserSecurityKey.where(user_id: user.id).destroy_all
UserSecurityKey.where(
user_id: user.id,
factor_type: UserSecurityKey.factor_types[:second_factor],
).destroy_all
UserSecondFactor.where(user_id: user.id, method: UserSecondFactor.methods[:backup_codes]).each(
&:destroy!
)
puts "2FA disabled for #{username}"
end