Thanks to visit codestin.com
Credit goes to github.com

Skip to content
This repository was archived by the owner on Jun 12, 2018. It is now read-only.
This repository was archived by the owner on Jun 12, 2018. It is now read-only.

Request MFA code to validate MFA activation #373

@ook

Description

@ook

What?

When we enable MFA (multi factor authentication), cozy doesn't request any confirmation. Here the list of problems:

  • some users won't understand what this feature is and they'll lock them out of their cozy
  • some users have a bad clock setup on their device / server and won't discover it before the next login when… they'll be locked out their instance

How?

Don't enable MFA until enter a valid code from their other device.
All major service use this scheme and can be used as an exemple: heroku, github, google, etc.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions