born05 / craft-twofactorauthentication

Craft plugin for two-factor or two-step login using Time Based OTP.
MIT License
36 stars 26 forks source link

Impersonating Users #65

Closed adampatpattison closed 1 year ago

adampatpattison commented 2 years ago

We've recently implemented this plugin and set forceBackEnd to true.

Admin's or other users with the "Impersonate Users" permission are now asked to either setup 2FA or enter the user they're impersonating's verification code.

Is there a way to subvert this when using the CraftCMS impersonate user option?

roelvanhintum commented 1 year ago

Sorry for the late response, but it i think it comes with to much vulnerabilities to change this behavior.