OpenListTeam / OpenListTeam/OpenList

[Feature] 是否考虑为双因素认证添加recovery code

Open
#2,176 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement has-parent Module: User
Dominant language
Go
Stars
24.7k
Forks
2.3k
Avg merge
1d 20h
Merged PRs (30d)
36

Description

请确认以下事项
  • 我已确认阅读并同意 AGPL-3.0 第15条
    本程序不提供任何明示或暗示的担保,使用风险由您自行承担。

  • 我已确认阅读并同意 AGPL-3.0 第16条
    无论何种情况,版权持有人或其他分发者均不对使用本程序所造成的任何损失承担责任。

  • 我确认我的描述清晰,语法礼貌,能帮助开发者快速定位问题,并符合社区规则。

  • 我已确认阅读了OpenList文档

  • 我已确认没有重复的问题或讨论。

  • 我认为此问题必须由OpenList处理,而非第三方。

  • 我已确认此功能尚未被实现。

  • 我已确认此功能是合理的,且有普遍需求,并非我个人需要。

  • 我没有阅读这个清单,只是闭眼选中了所有的复选框,请关闭这个 Issue 。

需求描述

大多数双因素认证都会有一个recovery code功能,以便在OTP设备故障,或者无设备时临时通过二次认证,没有离线验证码的话,就必须依靠验证器,所以希望考虑完善一下双因素认证,毕竟开放在公网的openlist使用双因素是对安全的极大保障,但是也需要保证有一个“备用钥匙”

实现思路

参考市面上其他双因素认证即可

附加信息

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue does not name files, tests, or entry points. Start by locating OpenList's existing two-factor authentication flow and reviewing how OTP verification is handled. Done means users can securely generate, store, and use recovery codes when their OTP device is unavailable, with appropriate recovery-code lifecycle behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
authentication, backend, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.