imtbl / hyve

Expose and consume your hydrus media via HTTP API
GNU Affero General Public License v3.0
31 stars 3 forks source link

Feature Request: TOTP for User Accounts #3

Open Ryonez opened 4 years ago

Ryonez commented 4 years ago

It's be nice to see a bit of extra security added to the accounts.

imtbl commented 4 years ago

I don't dislike the idea but also don't find it very critical to have as the user accounts don't store any personal data at all and are only a means to access the media if you choose to not make them public. Granted, the media could be very private, but in that case I'd probably use other means to protect them anyway (e.g., non-public facing servers, limiting to specific IPs/requiring a VPN).

As it is quite a bit of effort to implement, I don't think I'll work on this any time soon. I'll leave the issue open though in case someone wants to tackle it and make a PR.