OpenFn / OpenFn/lightning

Either Password or 2FA for accessing Webhook Auth info, not both

Open
#1,579 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Elixir
Stars
296
Forks
86
Avg merge
1d 13h
Merged PRs (30d)
50

Description

For security purposes, we require a user to add their username and password when viewing the password or API key for the Webhook authentication method.

Currently (see screenshot attached), the user has the option of selecting either the password or 2FA code to view it, which is incorrect:

  • If 2FA is not enabled for user: Request Password
  • If 2FA is enabled for user: Request 2FA code

This adheres to the users security preference of having 2FA enabled.

image.png

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the Webhook authentication method's flow for viewing its password or API key, and trace how the password and 2FA choices are presented. Verify the behavior for users with 2FA disabled and enabled, ensuring each case requests only the corresponding security factor.

Written by the indexing model from the issue text.

Assessment

Tech stack
elixir
Domain
authentication, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.