two-factor-authentication
Here are 239 public repositories matching this topic...
I love the library and it has been very helpful for me.
Recently, my implementation of speakeasy.totp failed a penetration test. I wrote a writeup on my findings (with a code sample to show how common this can happen with a bad implementation+configuration).
The issue: please improve the documentation (especially arou
It would be helpful to have a comprehensive documentation of the endpoints to help configure Authelia correctly in real life environments.
-
Updated
Apr 5, 2020 - PHP
It might be useful to have a generic system for documenting anything within PrivacyIDEA. However that is a rather large undertaking.
See: #1814
We could have a table for documentation and then add links in this table where it links to.
But the questions would be
- where display the documentation
- to whom display the documention?
- for users?
- for admins?
Hi, I followed the example site and managed to get the "secret" page working with 2FA setup on my website.
However, to protect the admin site, I found this ReadTheDocs article, but it doesn't seem to work. Is this procedure still the current way to make 2FA work on the admin site ?
Using this, when I go to t
-
Updated
Jul 3, 2020 - PHP
-
Updated
Jul 7, 2020 - TypeScript
Please add some sort of indicator when a code is due to expire. Having the about-to-expire code blink would be more than sufficient.
-
Updated
Jun 7, 2020 - PHP
In our environment, we auto generate a number of profiles and we use a comment
START of Generated Lines
To separate out the generated profiles from the non-generated one. Unfortunately, everytime we run the aws-mfa tool, it removes that comment.
-
Updated
May 18, 2020 - Go
-
Updated
Jun 30, 2020 - PHP
-
Updated
May 23, 2020 - Go
UnhandledPromiseRejectionWarning: Unhandled promise rejection (rejection id: 742): UnableToResolveError: Unable to resolve module prop-types from /home/********/Downloads/react-native-phone-verification-master/example/node_modules/react-native-emoji/index
[Edit by @cbetta]
Add documentation on what callback actually is. For most people it's clear to be a function but even then it would be good to document what to expect exactly.
[Original issue]
Hello there,
would it be possible to add the response to all function calls ?
Otherwise I am unable to determine if for example an SMS message was sent.
Cheers.
-
Updated
Jul 4, 2020 - Ruby
-
Updated
Apr 2, 2019 - Go
-
Updated
Jul 7, 2020 - Swift
-
Updated
Jun 19, 2020 - Ruby
When using TOTP the user password should -always- go to the TOTP app, even if wrong.
It should not say "wrong password" prior to the TOTP app for security reasons. This app should not let the attacker know they have the correct password!
Current behavior:
Attempt login - wrong password - error
Attempt login - correct password - totp - error | This lets the attacker know the password is c
-
Updated
Mar 19, 2020 - Go
-
Updated
Jun 24, 2020 - PHP
-
Updated
Jul 8, 2020 - Python
-
Updated
Jun 21, 2020 - Clojure
-
Updated
Jun 19, 2020 - JavaScript
-
Updated
Mar 9, 2018 - HTML
-
Updated
Mar 21, 2018 - JavaScript
Improve this page
Add a description, image, and links to the two-factor-authentication topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the two-factor-authentication topic, visit your repo's landing page and select "manage topics."

Yahoo Japan supports one time passwords using their own app. Their info page about it: https://id.yahoo.co.jp/security/otp.html
andOTP did not recognize their QR code. It's encoded as:
Also tried copy-paste but that resulted in wrong values; I might have done something wrong.
andOTP produces the correct values when enter