paragonie / airship

Secure Content Management for the Modern Web - "The sky is only the beginning"
https://cspr.ng
Other
418 stars 41 forks source link

Enabling 2FA should require TOTP #81

Open kelunik opened 8 years ago

kelunik commented 8 years ago

Setting up 2FA shouldn't be done with a checkbox while the QR code is always shown. It should show the QR code only after a click on a setup button and require a first valid code to be entered then to ensure the user has set it up properly. Only after that, 2FA should be in an enabled state.

paragonie-scott commented 8 years ago

Okay, I'll rebuild that feature in version 2. :)