lemon-flag-71975
04/17/2023, 3:17 PMrequired_aal
to aal1
it effectively allows attacker with user credentials to regenerate their MFA
But if I set it to highest_available
then user’s can’t reset their own MFA during account recovery flow
Am I missing something? Is there maybe an admin API for managing user’s MFA settings?dazzling-napkin-4938
04/18/2023, 1:47 AMdazzling-napkin-4938
04/18/2023, 1:53 AMlemon-flag-71975
04/18/2023, 7:48 AMdazzling-napkin-4938
04/18/2023, 7:52 AMsteep-lamp-91158
dazzling-napkin-4938
04/19/2023, 12:02 AM