Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable check #22

Open
rullzer opened this issue Oct 18, 2018 · 9 comments
Open

Enable check #22

rullzer opened this issue Oct 18, 2018 · 9 comments

Comments

@rullzer
Copy link
Member

rullzer commented Oct 18, 2018

As mentioned by @tobiasKaminsky

Maybe it would make sense to force a notification acceptance from a device other than a browser. So either mobile device (IOS/Android) or the desktop client. At least not the same browser as we are working from.

That way we verify people at least at that point have access to a second device.

@nickvergessen
Copy link
Member

You should not be able to receive notifications in the same browser while trying to log in?

@rullzer
Copy link
Member Author

rullzer commented Oct 19, 2018

@nickvergessen you do not. It when you enable. That you have to proof you have access to another session.

@tobiasKaminsky
Copy link
Member

@nickvergessen this is to prevent following situation:

  • create new user
  • log in into web browser (only one and only session)
  • turn on 2f notification
  • log out
    --> now you can never ever login again

@rullzer
Copy link
Member Author

rullzer commented Feb 6, 2019

This could be done by a special notifiation and then parsing to show it or not depending on the user agent.

@rullzer rullzer self-assigned this Feb 6, 2019
@TheHendla
Copy link

I have activated 2FA on my Admin account and logged out for testing without a second active session. How i can got access back? At least i thought, there is a check for 2 active session?!

@nickvergessen
Copy link
Member

./occ twofactorauth:disable <your userid>

@ghost
Copy link

ghost commented Jun 15, 2020

I cut the branch under my butt too.
I still have a ftp access, but I am a beginner and don't know where to insert this line.
Do you have a helpful tip?

Greeting

@IanNicki
Copy link

This issue might be set as done. It is already working on the iOS / iPadOS Nextcloud application.
Can anybody confirm that it is also working on Android?

@nickvergessen
Copy link
Member

There is no such check yet before setting up the provider.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants