[web] Add some kind of multi factor login
- Dominant language
- Go
- Stars
- 9.2k
- Forks
- 1.3k
- Avg merge
- 12h 58m
- Merged PRs (30d)
- 56
Description
Currently the website has a simple single factor login.
So after my password has been compromised one could go to the website and from there do at least the following:
* Reset my account
* Delete my account permanently
Both are very destructive actions.
I'd like if there were some kind of a second factor which involves confirming the login via at least one device (if available).
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue does not identify files, tests, or an entry point. Scope the web login flow and the proposed device-confirmation approach first; done would require an agreed second-factor design that protects destructive account actions.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security, web-dev
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100