Skip to content

Ebbwell 0.4.0 — two-factor authentication

Choose a tag to compare

@Maxren2 Maxren2 released this 28 Sep 06:28
· 14 commits to main since this release

Two-factor authentication for local accounts

  • Standard authenticator apps (TOTP, RFC 6238): Aegis, 2FAS, Google/Microsoft Authenticator, 1Password… Set it up in Settings → Account by scanning a QR code or typing the key.
  • 10 single-use recovery codes, shown once. You can create new ones later with your password plus a current code.
  • Sign-in: after the password, a code prompt (a recovery code works too). A code can't be reused, and wrong codes count toward the account lockout.
  • Policy: LOCAL_2FA=optional|required. With required, every local user must set it up right after their password before using the app. Recommended if you use LOCAL_LOGIN=everywhere.
  • Storage: the secret and recovery codes are encrypted at rest and covered by key rotation.
  • Lost phone and recovery codes: an administrator can use Reset two-factor, or run docker exec <container> node server/cli.ts disable-2fa <user>.

Single sign-on users keep using their identity provider's MFA (e.g. Authentik).

Image: ghcr.io/maxren2/ebbwell:0.4.0. See docs/DEPLOY.md §2.