Improving Access Tokens
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
## Feature Request
**IP Security**
Whenever a user signs up, a access token contains the IP that will be kept on being used and inform this on signup form.
Whenver they login without the ip that was gaven during sign-up, They will reset their password (email + ui saying to check email and to resend the emails, and not allow them to access the site until they do reset it) OR they can get an email to authorize the IP and show an error message saying to check the email. (setting chosen in admin dash)
**Justifing why this feature belongs in Flarum's core, rather than in a third-party extension**
This feature should belong to the flarum core because rather an extension handling this security risks, the flarum core can handle it and always be up-to-date, and can prevent users having to wait for 3rd parties to update the security extension.
Contributor guide
Research direction
The issue does not name files, tests, or entry points. Start by mapping the signup, login, password-reset, email-authorization, and admin settings flows, then clarify which IP policy should be supported. Done would require an agreed security design and complete implementation across those flows, with tests for the selected behavior.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100