Loading...
 
Skip to main content

Admin should be able to impose 2 factor authentication to users

Status
Open
Subject
Admin should be able to impose 2 factor authentication to users
Version
27.x
28.x
master
Category
  • Usability
  • Feature request
Feature
User Administration (Registration, Login & Banning)
Resolution status
Confirmed
Submitted by
Bernard Sfez / Tiki Specialist
Lastmod by
Bernard Sfez / Tiki Specialist
Rating
(0)
Related-to
Description

On Tiki an admin can enable "Allow users to use 2FA" in the log-ion area /tiki-admin.php?page=login#Users Management

https://doc.tiki.org/Two-factor-authenticationQuestion

But this step is not enough as each user has to go individually to its user preferences (replace userId by an existing one) /tiki-user_preferences.php?userId=3#contentmytiki_user_preference-4 and enable it. So it is totally a user choice to use or not 2FA.

At /login or /tiki-login_scr.php?twoFactorForm if the user tries to login without a code pin he will simply login with his username and password.


We can consider very common for an admin to set and impose 2FA for login into a site.
We should have an option to make it mandatory including links and/or email notification to allow users to set their Pin Code, etc.


In a previous version Tiki18 - 21 the feature was imposed to the users as when this feature was enabled, the user was forced to enter a code received by email. May be we could have both options as it was way much simpler and user friendly (easier).

Solution
Workaround
Importance
5
Easy to solve?
5
Priority
25
Demonstrate Bug on Tiki 19+
Demonstrate Bug (older Tiki versions)
Ticket ID
8697
Created
Monday 30 September, 2024 12:25:04 UTC
by Bernard Sfez / Tiki Specialist
LastModif
Saturday 19 October, 2024 10:02:35 UTC


Show PHP error messages