Visitar URL original
Updating MFA methods for user with TOTP active results in error · Issue #2995 · firebase/firebase-admin-node · GitHub
Skip to content

Updating MFA methods for user with TOTP active results in error #2995

Description

@grzegorzjudas

[REQUIRED] Step 2: Describe your environment

  • Operating System version: macOS 15.6.1
  • Firebase SDK version: 13.5.0
  • Firebase Product: auth
  • Node.js version: 20.19.2
  • NPM version: 11.6.2

[REQUIRED] Step 3: Describe the problem

When attempted to change anything in the MFA configuration of a user that has TOTP active, firebase throws.

Steps to reproduce:

See the following example, where I attempt to enroll user with phone factor.

let enrolledFactors = (user.multiFactor?.enrolledFactors || []) as unknown as firebase.auth.UpdateMultiFactorInfoRequest[];

if (enrolledFactors.find((f) => f.factorId === method)) {
    console.log(`User ${email} is already enrolled in MFA method: ${method}`);
    return;
}

await firebase.auth().updateUser(user.uid, {
    multiFactor: {
        enrolledFactors: [
            ...enrolledFactors,
            {
                uid: `phone:${sanitizePhoneNumber(phoneNumber)}`,
                factorId: FactorId.PHONE,
                phoneNumber,
            },
        ],
    },
});

If the enrolledFactors include an entry with factorId totp, it throws:

FirebaseAuthError: Unsupported second factor "{"uid":"58637419-3818-4e95-b26c-7254aa11a85b","displayName":"TOTP","factorId":"totp","enrollmentTime":"Fri, 24 Oct 2025 09:34:05 GMT","totpInfo":{}}" provided.

It does look like the firebase-admin does not support TOTP fully, even though user was able to enroll and use the TOTP method on the client just fine - and the user.multiFactor?.enrolledFactors do return it (but you can't save it back to the firebase).

Activity

  1. removed theissue type on Oct 27, 2025
  2. grzegorzjudas commented on Oct 28, 2025

    @grzegorzjudas
    Author

    Also one note regarding TypeScript definitions. The enrolledFactors array (2nd argument of the updateUser call) is of type MultiFactorUpdateSettings.enrolledFactors: UpdatePhoneMultiFactorInfoRequest[] | null which definitely suggests it wasn't updated to a more generic type that also supports TOTP (the type returned from user.multiFactor?.enrolledFactors is MultiFactorInfo[] | undefined.

  3. L-L-B commented on Jan 27, 2026

    @L-L-B

    @grzegorzjudas Did you manage to get past this?

    I'm experiencing the same problem with updating users who have an existing TOTP factor configured.

    @pashanka Are there any plans to address this? or a workaround if not!

  4. grzegorzjudas commented on Feb 20, 2026

    @grzegorzjudas
    Author

    I haven't, frankly. The TOTP support on Firebase has a lot of space for improvements on all fronts, looks like. I'm not actively trying to work around this problem but my best guess if I had to try would be to use REST API.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions