Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

As an administrator I need to be able to turn off tfa for specific users #47

Open
aweingarten opened this issue Jul 5, 2016 · 6 comments

Comments

@aweingarten
Copy link

aweingarten commented Jul 5, 2016

Currently a user must login as an admin, attempt to turn it off 2fa for a user, get prompted for a password and then enter the password.

Its impossible to do this for an admin that relies on drush uli to turn off 2fa. You get prompted for a password you don't know! Administrators should be able to disable 2fa without being prompted for a password.

@nerdstein
Copy link

The same could be said for the Masquerade module, but that would be after a user is logged in

@nerdstein
Copy link

@aweingarten --- what do you think the best way to solve this is? clearly we need to keep the security intact but walk us through what you think would be a good means for resolving this.

@nerdstein
Copy link

We need a permission that bypasses the secondary password check if you have the permission.

Basically, as an admin, I could be granted a "manage user tfa" permission which would NOT prompt me for a secondary password check

@aweingarten
Copy link
Author

We already have an "Administer users" permission which is used to manage users and password. Can reuse that.

Keep "Administer TFA" for the global site wide settings.

@therealssj
Copy link

yes, administer users seems to be better, was just writing that.
It is already used in TFA at some positions.

@nerdstein
Copy link

I like that idea.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants