Fix incorrect handling of user verification failure response #35629
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Reported in https://discord.com/channels/188630481301012481/1097318920991559880/1435953371247939594.
VerificationFailureResponse.RequiredSessionVerificationMethodnot being nullable means that if it was missing in the verification response, it would not benullbut default toTimedOneTimePasswordinstead, therefore showing TOTP-related error messages to users that never enabled it rather than the user-facing message they were supposed to via theosu/osu.Game/Online/API/APIAccess.cs
Lines 294 to 297 in 5eda9a0
Most easily tested on a local full-stack environment with
applied so that you don't have to wait 10 minutes to trigger the failure.