diff --git a/lib/private/legacy/api.php b/lib/private/legacy/api.php index a4745f58d0..1e581153ce 100644 --- a/lib/private/legacy/api.php +++ b/lib/private/legacy/api.php @@ -341,6 +341,10 @@ class OC_API { // reuse existing login $loggedIn = \OC::$server->getUserSession()->isLoggedIn(); if ($loggedIn === true) { + if (\OC::$server->getTwoFactorAuthManager()->needsSecondFactor()) { + // Do not allow access to OCS until the 2FA challenge was solved successfully + return false; + } $ocsApiRequest = isset($_SERVER['HTTP_OCS_APIREQUEST']) ? $_SERVER['HTTP_OCS_APIREQUEST'] === 'true' : false; if ($ocsApiRequest) {