-
-
Notifications
You must be signed in to change notification settings - Fork 4.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Administrative changes should be confirmed by an 2FA token instead of a password by default #7288
Comments
This would introduce a hard dependency on the U2F app which now is completely independent. |
@ChristophWurst The twofactor_u2f app already allows to replace or better complete the login process, so it should also be possible to replace the password request if the app has been installed and activated. |
I'm not aware of any. |
The issue has still not been fixed in Nextcloud v13.0.6. |
This is also just an enhancement. Also this ticket is not closed so it is also not fixed in master, nor in 14 and not even in 13. First we need to find time to look into this, then find a technical solution, implement it and then in can be tested. |
@MorrisJobke I understand. Due to the fact that the issue has automatically been classified as stale I worried if this would be the last step before automatically closing the ticket. |
Similar request (with TOTP) in #13025 |
Unfortunately the described feature is not really high on our priority list. But this doesn't mean that we don't like the idea or that we are against this feature per se. Quite the opposite! 🙂 There are many way to get new features in Nextcloud:
|
Status? |
Expected behavior
If the twofactor_u2f app has been installed and an external U2F key has been registered all password confirmation dialogs should be replaced by an U2F key confirmation.
Current behavior
If you're going to change a personal setting, a confirmation is usually be requested. Although the twofactor_u2f app has been installed and an external U2F key has been registered, the login password need to be entered manually instead of requesting a confirmation via the available U2F key.
Steps to reproduce
Environment
Server Configuration
OS: Linux 3.16.47
Web server: Apache2 2.4.29
Database: MariaDB 10.0.32
PHP version: 5.6.29
Nextcloud version: 12.0.3
Client Configuration
Browser: Mozilla Firefox 57.0
Operating system: Windows 7
The text was updated successfully, but these errors were encountered: