Skip to content

v1.18.0

Choose a tag to compare

@hreskiv hreskiv released this 01 May 08:09
· 45 commits to main since this release

Security

  • Two-factor authentication (TOTP) — opt-in per user. Open Settings → Security → Enable two-factor authentication, scan the QR with any authenticator app (Google Authenticator, Authy, 1Password, Microsoft Authenticator, …), confirm with a 6-digit code, then save the 8 backup codes shown — each works once if you lose access to your authenticator. After enabling, sign-in becomes a two-step flow: password, then code. Admins see a 2FA column on the Users page and a Reset 2FA button to clear it for someone who lost their device. Existing users without 2FA keep signing in exactly as before — nothing forced.