Skip to content

Avoid security-key dead-end on re-auth in non-account apps - #501

Open
Sea-n wants to merge 4908 commits into
ProtonMail:mainfrom
Sea-n:org-setup-2fa
Open

Sea-n wants to merge 4908 commits into
ProtonMail:mainfrom
Sea-n:org-setup-2fa

Conversation

@Sea-n

@Sea-n Sea-n commented May 2, 2026

Copy link
Copy Markdown

As a new Business plan user, when I click Org setup in the Proton Calendar navbar, I'm asked for an organization name. After entering it and then my password, the flow fails: "security key sign-in isn't supported on the calendar.proton.me subdomain".

Steps to reproduce

  1. Use a new org account (no org name yet).
  2. Set up a security key, leaving TOTP unused.
  3. Open calendar.proton.me.
  4. Click Org setup in the navbar.
  5. Enter any org name and submit.
  6. Enter your password and submit.
  7. Error: "Security key sign-in is not supported on this application, please use https://account.proton.me".

Fix

A. Pre-check in SrpAuthModal

When userSettings indicates FIDO2-only 2FA on a non-account app, render a "Continue in Proton Account" redirect screen instead of the password form. Avoids letting the user submit a password that's destined to fail. A "Continue here anyway" escape hatch preserves the original flow for edge cases (e.g. admin signed in as sub-user) where userSettings is misleading; the authoritative /auth/info check still runs on submit.

This also covers ChangeOrganizationPasswordModal, ChangeOrganizationKeysModal, and other admin actions using unlockPasswordChanges() with scope="password".

B. Gate in B2B Onboarding

Add a warning banner + Proton Account link above the org-name input, so the user doesn't invest time entering information in a place where it can't be saved.

Caveats

  • I couldn't figure out how to remove my own org name on production once it's set, so I'm unable to reproduce the exact original flow again or capture before/after screenshots.
  • I haven't set up the project locally, so to be honest I haven't actually run this; code-wise LGTM, but it needs someone with a working dev environment to verify the behavior end-to-end.
StraightOuttaCrompton and others added 30 commits April 27, 2026 12:31
… handling

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…'main'

Improve UX flow when SMS sending fails for disabling 2fa flow

See merge request web/clients!24472
Update the URL when category view feature flag or setting is toggled

See merge request web/clients!24463
Force the forum categories into the disabled categories

See merge request web/clients!24391
[DRVWEB-5350] fix SharingModal click through

See merge request web/clients!24481
Minor fixes for lumo 1.4

See merge request web/clients!24482
Docs: Point Help menu to Drive support hub for documents

See merge request web/clients!24427
Docs: Wrap "Save for later" label in public header dropdown

See merge request web/clients!24425
Docs: Prevent DropdownItem flex items from wrapping

See merge request web/clients!24426
fix(INDA-683): Remove parameter sanitization for proton URLs, prevent spammy...

See merge request web/clients!24488
Sheets: auto-select title on focus only when name is default

See merge request web/clients!24452
@mmso
mmso force-pushed the main branch 9 times, most recently from 5eb5e79 to 28d81d1 Compare September 11, 2026 16:16
@mmso
mmso force-pushed the main branch 6 times, most recently from aa7e8fc to 26b447f Compare September 21, 2026 12:20
@mmso
mmso force-pushed the main branch 6 times, most recently from 6cb99ea to a0a8848 Compare September 24, 2026 14:16
@mmso
mmso force-pushed the main branch 8 times, most recently from 57fccbd to c51e81b Compare October 1, 2026 20:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet