Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Force 2FA for Administration #48

Open
zolthan opened this issue Feb 14, 2023 · 5 comments
Open

Force 2FA for Administration #48

zolthan opened this issue Feb 14, 2023 · 5 comments
Labels
enhancement New feature or request

Comments

@zolthan
Copy link

zolthan commented Feb 14, 2023

Hi @runelaenen ,

do you think it's possible to force backend users to use the 2FA before using the rest of the administration? We have a customer whose admin users have to use the 2FA. Currently it is optional to use the 2FA and the users normally use the easy way without 2FA.

I could think of a message on login on the right side in the message center, or a forced redirect to the profile where the 2FA can be configured.

What do you mean?

Best
Sebastian

@runelaenen runelaenen added the enhancement New feature or request label Feb 21, 2023
@zolthan
Copy link
Author

zolthan commented Apr 24, 2023

Hi @runelaenen
do you plan to implement this feature in the near future? One of our customers has a policy that 2FA has to be used by admin users. Currently only a few of them are using it as they are not forced to use it.
Best
Sebastian

@runelaenen
Copy link
Owner

Hello @zolthan

Thank you for reaching out. While I understand the importance of the mandatory 2FA feature for your customer's policy, I currently don't have the bandwidth to implement it myself.
However, I welcome contributions from the open source community and encourage anyone interested in adding this feature to create a pull request. I would be happy to review and merge it once it meets the project's standards and requirements.

@zolthan
Copy link
Author

zolthan commented Apr 24, 2023 via email

@zolthan
Copy link
Author

zolthan commented May 23, 2023

Hi @runelaenen ,

we created this feature as a patch for our current version 1.1.2 we are running in the shop. Unfortunately it makes no sense to create a pull request for an old version. Maybe you can apply the patches to the current version so it will be available for the future 6.5 updates.

I hope it helps you.

Best, Sebastian

force2fa_id_js.patch
force2fa.patch

@zolthan
Copy link
Author

zolthan commented Jan 29, 2024

Hi @runelaenen ,
did you look into our patches? Could you please add the feature to the plugin? Our customers who have Backend-2FA are using it mandatory. So no Backend-User can login without first going through the 2FA process.
Best
Sebastian

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants