Skip to main content

3 posts tagged with "dashboard"

View All Tags

Backup codes: regenerate any time, and they survive adding an authenticator

One set of backup codes covers every way you sign in, whether you use a passkey, an authenticator app, or both.

  • Regenerate backup codes is now available in Settings → Security, including for accounts that only use a passkey. Replacing the set invalidates the old codes immediately and needs a fresh confirmation from you.
  • Adding an authenticator app no longer replaces your codes. If your account already has backup codes, they stay valid and the setup screen says so. Before this change, enabling an authenticator app generated a new set and silently invalidated the one you had saved.

One password rule everywhere

Every place that sets a password now applies the same rule: at least 8 characters, including a lowercase letter, an uppercase letter and a number. A symbol is welcome but does not replace a number.

  • The sign-up, set-password, reset-password and change-password forms all check the rule before you submit, so a password the server would refuse can no longer look acceptable.
  • The API returns a single message for every violation: "Password must be at least 8 characters and include a lowercase letter, an uppercase letter and a number".
  • If setting the password fails after your verification code was accepted, you can retry without requesting a new code.
  • The sign-up password form now includes your email as the username, so your browser's save-password prompt stores a complete login.

Sign-in: passkey first, codes as a deliberate second choice

If your account has both a passkey and an authenticator app, signing in now offers the passkey first. Your browser's passkey prompt opens by itself; if you dismiss it you can try again, or choose Use a code instead to enter an authenticator or backup code.

  • Passkey only: the code box asks for a backup code, and says why.
  • Authenticator app only: nothing changes.
  • Settings → Security: you can now rename a passkey, so you can tell your devices apart.

Also fixed: signing out after the page had been idle for a while could leave you signed in. Logout now ends the session reliably.