Steps to replicate the issue:
- Regenerate recovery codes from Special:AccountSecurity.
What happens?:
I was given only ONE recovery code.
It's not enough to disable 2FA safely without any other ways.
What should have happened instead?:
- Increase the recovery codes.
Instead, automatically disable 2FA when recovery code is used.
Software version (on Special:Version page; skip for WMF-hosted wikis like Wikipedia):
MediaWiki:1.45.0-wmf.22 (rMWd77754182d63)
Other information (browser name/version, screenshots, etc.):
Windows, Chrome
