Following up on T218211 and T232008
So testing the whole thing again…
This seems to have resulted in a weird workflow, that causes it to request a username and password (ie login again) after entering the OTP onto the enabling form... When really it should be asking *before* you try and enable 2FA...
Otherwise we're getting a workflow where you enable 2FA, but then are kicked out of your account. Which doesn't seem very UX friendly... Note, it only asks for username and password, it doesn't then give the 2FA box for you to fill in
(will flesh this out a bit when I've poked around a bit more)