[docs-scanner] 2FA account recovery instructions contain logical contradiction
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 72/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- docker
- Lĩnh vực
- authentication, documentation
Hướng nghiên cứu
Mở content/manuals/security/authentication/2fa/recover-hub-account.md và kiểm tra phần hiện tại "Recover your account without access". Xác minh quy trình đăng nhập và khôi phục 2FA thực tế của Docker, bao gồm việc tùy chọn thiết bị bị mất xuất hiện trước hay sau bước xác thực và liệu biểu mẫu Contact Support có bắt buộc hay không. Công việc được xem là hoàn tất khi các hướng dẫn khớp với trải nghiệm người dùng mà không đưa ra các bước mâu thuẫn.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
File: content/manuals/security/authentication/2fa/recover-hub-account.md
Issue
The "Recover your account without access" section instructs users to sign in with username and password when they've lost both their 2FA device and recovery code:
If you lost access to both your two-factor authentication application and your recovery code:
- Sign in to your Docker account with your username and password.
- Select I've lost my authentication device and I've lost my recovery code.
Why this matters
This is a logical contradiction that will confuse users in a critical account recovery situation. When 2FA is enabled on an account, signing in requires:
- Username and password
- The 2FA code from the authenticator app
If a user has lost their authentication device, they cannot provide the 2FA code, which means they cannot complete step 1 (signing in). The instructions don't explain how to bypass the 2FA prompt or access the "I've lost my authentication device" option without being able to sign in first.
A user following these instructions will be stuck at the sign-in page, unable to proceed to step 2 where they can indicate they've lost their device.
Suggested fix
Clarify the actual recovery flow. Possible approaches:
-
If there's a "lost device" link on the sign-in page itself (before completing authentication), explain that:
- Go to the sign-in page
- Enter username and password
- When prompted for 2FA code, select "I've lost my authentication device"
- Then select "I've lost my recovery code"
-
If users must contact support without being able to sign in at all, simplify to:
- If you've lost both your authentication device and recovery code, you cannot sign in
- Complete the Contact Support form with your primary email address for recovery instructions
The instructions should match the actual user experience when 2FA blocks sign-in.
Found by nightly documentation quality scanner
- Ngôn ngữ chính
- Markdown
- Star
- 4.7k
- Fork
- 8.5k
- Merge trung bình
- 2 ngày 18 giờ
- Pull request đã merge (30 ngày)
- 121
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của docker/docs
-
Instructions no longer valid Đang mởstatus/triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 95/100
Issue tương tự
-
good first issue
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 95/100
AOSSIE-Org/DebateAI#582 · 2 bình luận ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
oasisprotocol/oasis-sdk#2523 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
cost:cheap severity:medium
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
fairagro/m4.2_sql_to_arc#227 ·