getgrav / grav-plugin-admin

Grav Admin Plugin
http://getgrav.org
MIT License
354 stars 227 forks source link

Pass a 2FA challenge (+ password?) before activating it #1659

Open Zykino opened 5 years ago

Zykino commented 5 years ago

Check the use know what he is doing before being locked out of his own CMS. All the websites I tryed asked me to pass a 2FA challenge before finishing the enabling process: Github, Discord...

mahagr commented 5 years ago

You can disable the setting by just editing your user from user/accounts folder.

Zykino commented 5 years ago

That's if have access to the machine, or setted up the git plugin. Someone may have setted me a Grav website, with the Admin plugin but no direct access to the host's filesystem.

Also there is the case of: I set up 2FA.

I proposed this to have the same UX as other website. I do not think adding recovery is needed because of the file edition you pointed but maybe it's needed too.