forwardemail / forwardemail/forwardemail.net
[feat] 2FA support for Alias accounts
- Dominant language
- JavaScript
- Stars
- 1.7k
- Forks
- 203
- PR merge metrics
- No merged PRs in 30d
Description
## Describe the feature
2FA is already available for the main Forward Email account, but it would be nice to have it for Alias accounts as well (especially for use in https://mail.forwardemail.net when webmail is enabled).
For other clients (like Thunderbird), maybe custom app passwords can be used or guidance on needing to turn on 2FA after adding account to those clients could be suggested.
Currently, I think there is a risk of unauthorized access to an alias without anyone realizing it?
## Checklist
- [Yes] I have searched through GitHub issues for similar issues.
- [Yes] I have completely read through the README and documentation.
Contributor guide
Research direction
No files, tests, or entry points are named. Start by tracing the existing 2FA flow for the main Forward Email account and the Alias account authentication flow. Done means Alias accounts are protected in webmail, while the Thunderbird/app-password behavior and user guidance are clarified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100