AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Account Locked In 2FA Loop When MFA Was Never Enabled

Users with Pro accounts are unable to log in because Supabase Auth repeatedly requests a second factor (TOTP) despite no MFA factors being enrolled for the user. This locks the account in a loop after email/password authentication.

criticalConfidence 60%GoTrue

Origin Analysis

In GoTrue, the `aal` claim in the access token is incorrectly set to `aal2` even when the user has no enrolled MFA factors. The client interprets the `aal2` requirement as a need to perform MFA verification, redirecting to the MFA challenge. Since the user has no factor to verify, the loop continues indefinitely.
1. Sign up for Supabase Pro account without enabling MFA.\n2. Log out and attempt to sign in with email and password.\n3. Observe that after submitting password, the application prompts for a 6-digit TOTP code.\n4. Because no TOTP factor is enrolled, the user cannot provide a valid code and is stuck.

Fixing Code Block

Edge Case Audit

This hotfix may inadvertently downgrade sessions for users with active MFA if `HasFactors()` implementation changes or if factors are not yet loaded; ensure to test with users who have enrolled TOTP. Rollback by reverting the patch and redeploying GoTrue. For already locked accounts, administrators should manually disable MFA via the `supabase.auth.admin.deleteFactor` API or by clearing `auth.mfa_factors` for the affected user before applying the patch.

Ecosystem Topology