forwardemail / forwardemail/forwardemail.net

[feat] 2FA support for Alias accounts

Open
#543 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
JavaScript
Stars
1.7k
Forks
203
PR merge metrics
No merged PRs in 30d

Description

## Describe the feature

2FA is already available for the main Forward Email account, but it would be nice to have it for Alias accounts as well (especially for use in https://mail.forwardemail.net when webmail is enabled).

For other clients (like Thunderbird), maybe custom app passwords can be used or guidance on needing to turn on 2FA after adding account to those clients could be suggested.

Currently, I think there is a risk of unauthorized access to an alias without anyone realizing it?

## Checklist

- [Yes] I have searched through GitHub issues for similar issues.
- [Yes] I have completely read through the README and documentation.

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by tracing the existing 2FA flow for the main Forward Email account and the Alias account authentication flow. Done means Alias accounts are protected in webmail, while the Thunderbird/app-password behavior and user guidance are clarified.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.