Ebbwell 0.4.0 — two-factor authentication
Two-factor authentication for local accounts
- Standard authenticator apps (TOTP, RFC 6238): Aegis, 2FAS, Google/Microsoft Authenticator, 1Password… Set it up in Settings → Account by scanning a QR code or typing the key.
- 10 single-use recovery codes, shown once. You can create new ones later with your password plus a current code.
- Sign-in: after the password, a code prompt (a recovery code works too). A code can't be reused, and wrong codes count toward the account lockout.
- Policy:
LOCAL_2FA=optional|required. Withrequired, every local user must set it up right after their password before using the app. Recommended if you useLOCAL_LOGIN=everywhere. - Storage: the secret and recovery codes are encrypted at rest and covered by key rotation.
- Lost phone and recovery codes: an administrator can use Reset two-factor, or run
docker exec <container> node server/cli.ts disable-2fa <user>.
Single sign-on users keep using their identity provider's MFA (e.g. Authentik).
Image: ghcr.io/maxren2/ebbwell:0.4.0. See docs/DEPLOY.md §2.