## What kind of change does this PR introduce?
Allow users to sign in using a recovery code after being redirected to
the MFA verification page.
## Additional context
<img width="435" height="373" alt="image"
src="https://github.com/user-attachments/assets/968fd15e-3081-4aa2-b645-4e0d2ec2637c"
/>
<img width="494" height="404" alt="image"
src="https://github.com/user-attachments/assets/fd7cee49-dca7-4f1a-873a-293e21c68faa"
/>
## How to test
- Enable MFA on your account if needed
- Generate recovery codes if needed (make sure you actually saved the
recovery codes somewhere)
- Sign out
- Sign in and when redirected to the MFA verification page, click the
_Authenticate using a recovery code_ link
- Enter one recovery code
Check that:
- you're signed in
- when on [your account security
page](https://studio-staging-git-gildasgarcia-auth-1624-dashb-177251-supabase.vercel.app/dashboard/account/security),
you have one less code available
Then:
- Disable the `enableAuthRecoveryCodes` config cat flag
- Sign out
- Sign in and wait on the MFA verification page
Check that:
- the _Authenticate using a recovery code_ link is not displayed
- Accessing [the recovery code sign in
page](https://studio-staging-git-gildasgarcia-auth-1624-dashb-177251-supabase.vercel.app/dashboard/sign-in-recovery-code)
redirects you to the MFA page
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added recovery-code authentication as an alternative MFA sign-in
method.
* Added a dedicated recovery-code sign-in page with validation,
visibility controls, cancellation, and sign-out options.
* Added a link from the MFA sign-in screen when recovery codes are
available.
* Added loading and error states while checking recovery-code
availability.
* **Bug Fixes**
* Prevented valid recovery-code sign-ins from being redirected back to
the MFA prompt.
* Limited recovery-code settings to accounts with exactly one enrolled
authenticator.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Ali Waseem <waseema393@gmail.com>
## What kind of change does this PR introduce?
Once users have recovery codes generated, allow them to regenerate the
codes.
This PR also automatically check the _I have copied the codes_ after
clicking the _Copy to clipboard button_.
> [!NOTE]
> The _Delete my recovery codes_ button only appear on local and staging
environments
## How to test
- On an account that already have recovery codes generated
- You should see an admonition showing the remaining codes available and
allowing you to regenerate the codes
## Screenshots
<img width="706" height="193" alt="image"
src="https://github.com/user-attachments/assets/001bfa87-74f5-4867-8564-09cb6f91adb6"
/>
<img width="425" height="277" alt="image"
src="https://github.com/user-attachments/assets/711b139c-f806-4da2-a240-fa7e7fd8acd0"
/>
<img width="548" height="353" alt="image"
src="https://github.com/user-attachments/assets/d6521a09-3a7f-4198-b162-9effc218fee6"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Added a recovery-code modal with copy-to-clipboard support and
confirmation before closing.
- Added an option to regenerate MFA recovery codes with a confirmation
step.
- Recovery-code controls now appear when existing codes are available.
- Added loading, success, error, and retry states for recovery-code
generation and regeneration.
- **Bug Fixes**
- Updated the recovery-code generation error message to more accurately
describe the failed action.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## What kind of change does this PR introduce?
After users have set up a new MFA (first or not), we must:
- check whether recovery codes have already been generated
- if there are none, generate recovery codes and display them, "forcing"
users to copy them
- if already generated, show them how many are still available
> [!NOTE]
> The _Delete my recovery codes_ button in last screenshot only appear
on local and staging environments
## How to test
- On an account that doesn't have recovery codes generated yet and has
an MFA added
- You should see an admonition suggesting to generate the codes
## Screenshots
<img width="729" height="306" alt="image"
src="https://github.com/user-attachments/assets/79ba3870-4ef8-4571-9fd6-36eed20c9c24"
/>
<img width="550" height="356" alt="image"
src="https://github.com/user-attachments/assets/1632611a-996a-470d-b6cd-a4693b0f4602"
/>
<img width="719" height="205" alt="image"
src="https://github.com/user-attachments/assets/73cef611-05cf-4fac-bbd2-243f9b28e48d"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Added support for generating, copying, and confirming MFA recovery
codes.
- Added recovery-code status visibility, including remaining and
exhausted codes.
- Added the ability to delete recovery codes with confirmation.
- Added clear loading, success, and error states for recovery-code
actions.
- Recovery-code status refreshes after codes are generated or deleted.
- **Bug Fixes**
- Recovery-code notices now remain visible when all codes have been
used.
- Recovery-code dialogs can now be closed after generation errors.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->