Skip to content

Conversation

@charsbar
Copy link

@charsbar charsbar commented Apr 28, 2023

This PR is only to show a proof of concept of andk#292 . No intention of merging this year. Nor feature complete.

Some of the known TODOs are:

  • decide how to provide/store/accept recovery codes
  • action override; provide a way for pause admins to disable mfa for someone else (without submitting any validation code)
  • mail content
  • nice description / usage text
  • testing (manually, with and without mfa)
  • decide how to communicate with cpan clients (mfa_code field should be ok?)
  • decide where to add mfa stuff (currently only edit_cred, but upload, change password, and permission stuff should be some of the candidates)
  • update the MFA page properly after enabling/disabling

See andk#388 for basic usage of docker compose.

@charsbar charsbar marked this pull request as draft April 28, 2023 14:41
@charsbar
Copy link
Author

If MFA doesn't work well after restarting servers etc...

  • stop docker-compose, run docker system prune, and then start docker-compose again
  • remove the stored url (via QR code) from your smartphone

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant