mojaloop / project

Repo to track product development issues for the Mojaloop project.
Other
24 stars 15 forks source link

2 Factor Authentication for the portal #3699

Open ei-nghon-phoo opened 10 months ago

ei-nghon-phoo commented 10 months ago

User Story:

As a user concerned about the security of my account, I want to enable two-factor authentication using an authenticator app for accessing admin portal so that I can add an extra layer of security to my account and ensure that only I have access to it, even if my password is compromised.

Acceptance Criteria:

bushjames commented 7 months ago

Consultation with product council recommended to decide if 2FA should be enabled by default and require definite action to disable. On agenda for PC call 27 Feb 2024.

bushjames commented 7 months ago

Issue raised with product council. Discussion on the PC call (27 Feb 2024) concluded that 2FA for all portals should be supported in any "off-the-shelf" mojaloop version, enabled by default and requiring action to disable. This follows a "fail safe" and "secure by default" approach. Some further discussion of this topic is possible over the coming few days.