TKOaly / baseball-bat

Debt Management Service
https://bbat.tko-aly.fi
2 stars 1 forks source link

Multiple authentication levels #61

Open dogamak opened 5 months ago

dogamak commented 5 months ago

Users authenticated via magic links from invoices and reminder emails should be considered as less strongly authenticated as those who have authenticated via email auth codes or using the TKO-äly SSO. These users should not have access to their personal settings or to the admin-UI before the reauthenticate using a stronger method.