fix(auth): disable phone verification requirement for new users

This commit is contained in:
sharath 2025-07-22 10:58:32 +00:00
parent c0e8614210
commit 7b66d6d58c
No known key found for this signature in database
1 changed files with 2 additions and 2 deletions

View File

@ -563,8 +563,8 @@ async def get_authenticator_assurance_level(
# Existing users (grandfathered) - only require verification if AAL demands it
verification_required = action_required == 'verify_mfa'
phone_verification_required = is_new_user and is_phone_verification_mandatory()
verification_required = is_new_user and verification_required and is_phone_verification_mandatory()
phone_verification_required = False and is_new_user and is_phone_verification_mandatory()
verification_required = False and is_new_user and verification_required and is_phone_verification_mandatory()
logger.info(f"AAL check for user {user_id}: "
f"current_level={current}, "