Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
Discussion options

I find for the security of the accounts as well as for the Admin access, it would be still nice if one could activate a MFA

You must be logged in to vote

Replies: 2 comments · 4 replies

Comment options

I'll add this to the backlog. I see this being important as the project matures. I have other features I currently see as higher priority, but if people start requesting MFA, I will increase the priority.

You must be logged in to vote
4 replies
@TheHung184
Comment options

Hi, thank you for great tool. I also would like to have MFA ( maybe TOTP first ? ). I have recently experienced attach on my server so i really concern about security.

@balzack
Comment options

A quick glance in this area suggest integrating with FreeOTP, would this be a good first solution?

I have one small mobile release to make and then I will work on this feature afterwards.

@balzack
Comment options

+ @ZedSphere @gentilsol

I am working on this feature now. I am not sure if the admin dashboard should require 2FA for access, what is your opinion?

My concern is that if the admin makes a mistake configuring 2FA, they would need to manually update the database with the sqlite command from within the container. I think this would be too technical for most people.

I am currently leaning towards having 2FA with TOTP for account login, but leaving the admin login as it is, but could easily be convinced otherwise.

@balzack
Comment options

I was convinced otherwise, will add totp for admin access as well.

Comment options

+1 for this idea.

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
💡
Ideas
Labels
None yet
4 participants
Morty Proxy This is a proxified and sanitized view of the page, visit original site.