Skip to content

Implement Two-Factor Authentication (2FA) #39

Description

@Techhackontime999

Description

Add TOTP-based two-factor authentication for enhanced account security - a critical security feature for a professional networking platform.

Requirements

  • 2FA setup page: generate TOTP secret, show QR code for authenticator apps
  • Backup codes: generate 10 one-time-use backup codes on setup
  • Login flow: after password, prompt for TOTP code or backup code
  • "Remember this device" option (30-day cookie)
  • 2FA management: enable/disable, regenerate backup codes
  • Recovery flow: use backup codes if authenticator is lost
  • Admin enforcement: optional require 2FA for all users
  • Security audit log for 2FA events

Files to Create/Modify

  • linkup/users/models.py - Add otp_secret, �ackup_codes, is_2fa_enabled, wo_factor_device fields
  • linkup/users/views.py - Add 2FA setup, verify, manage views
  • linkup/users/forms.py - Add 2FA forms (TOTP input, backup code input)
  • linkup/templates/users/two_factor_setup.html - QR code + setup page
  • linkup/templates/users/two_factor_verify.html - Login verification page
  • linkup/static/js/2fa.js - QR code display, auto-submit

Acceptance Criteria

  • Users can enable 2FA with QR code setup
  • Login requires TOTP code after password
  • Backup codes work for login
  • 2FA can be disabled (requires current TOTP)
  • "Remember device" works for 30 days

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    advancedAdvanced levelbackendBackend/API workfeatureNew feature or requestfrontendFrontend/UI work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions