From cdf5ff7acd865b94c3e10642e2499205e32251a7 Mon Sep 17 00:00:00 2001 From: Anders Kaseorg Date: Tue, 21 Oct 2025 18:45:18 -0700 Subject: [PATCH] forms: Correct TOTP token minimum value to 0. A TOTP token value of 000000 is just as likely as any other value. Signed-off-by: Anders Kaseorg --- zerver/forms.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/zerver/forms.py b/zerver/forms.py index 3329cfab17..d6c15096bd 100644 --- a/zerver/forms.py +++ b/zerver/forms.py @@ -635,7 +635,7 @@ class AuthenticationTokenForm(TwoFactorAuthenticationTokenForm): """ otp_token = forms.IntegerField( - label=_("Token"), min_value=1, max_value=int("9" * totp_digits()), widget=forms.TextInput + label=_("Token"), min_value=0, max_value=int("9" * totp_digits()), widget=forms.TextInput )