HiEventsDev / Hi.Events

Open-source event management and ticket selling platform 🎟️
https://hi.events
GNU Affero General Public License v3.0
1.12k stars 103 forks source link

🌟 Additional login security (2FA/passkey/webauthn) #33

Open gitmotion opened 2 months ago

gitmotion commented 2 months ago

Is your feature request related to a problem? Please describe.

Describe the solution you'd like

Describe alternatives you've considered

Additional context Won't go as far as saying this is a bug or vulnerability as Stripe details can only be accessed through deployment. However without additional security like 2FA, someone could try to bruteforce passwords or try a leaked password and change the email without the user even knowing. Additional security could help here :)

daveearley commented 2 months ago

Thanks for reporting this @gitmotion! I'll fix the email issue ASAP. As for 2FA, that's definitely on the long term roadmap.

daveearley commented 2 months ago

@gitmotion This has now been fixed. I'll leave the ticket open as a 2FA feature request. Thanks again

gitmotion commented 2 months ago

@daveearley awesome. just pulled the latest image and saw that it was working flawlessly 👏🏼