Description
Add TOTP-based two-factor authentication for enhanced account security - a critical security feature for a professional networking platform.
Requirements
- 2FA setup page: generate TOTP secret, show QR code for authenticator apps
- Backup codes: generate 10 one-time-use backup codes on setup
- Login flow: after password, prompt for TOTP code or backup code
- "Remember this device" option (30-day cookie)
- 2FA management: enable/disable, regenerate backup codes
- Recovery flow: use backup codes if authenticator is lost
- Admin enforcement: optional require 2FA for all users
- Security audit log for 2FA events
Files to Create/Modify
- linkup/users/models.py - Add otp_secret, �ackup_codes, is_2fa_enabled, wo_factor_device fields
- linkup/users/views.py - Add 2FA setup, verify, manage views
- linkup/users/forms.py - Add 2FA forms (TOTP input, backup code input)
- linkup/templates/users/two_factor_setup.html - QR code + setup page
- linkup/templates/users/two_factor_verify.html - Login verification page
- linkup/static/js/2fa.js - QR code display, auto-submit
Acceptance Criteria
Description
Add TOTP-based two-factor authentication for enhanced account security - a critical security feature for a professional networking platform.
Requirements
Files to Create/Modify
Acceptance Criteria