Conversation
Five places, one per question a reader arrives with: - preferences: the four policies, and that turning it back off deletes nothing; - generalities: how a member enables it, which applications to use, and that the ten recovery codes are shown once and want printing; - members: how an administrator resets one, with the reminder that a phone call asking for a reset is exactly how somebody would try to get a protection removed; - FAQ: clock drift first -- it refuses every code while everything else looks normal -- then the single use of a code, the lost device, and the super administrator, which has no recovery codes and is cleared from the database; - post installation: keep the server clock right, and keep an access to the database before enabling it on the super administrator. No screenshots yet: the interface is still under review.
They are written and tested but not offered in 1.3.0: under a compulsory policy a server clock that drifts or an enrolment that goes wrong puts a whole association outside its own instance, and the only way back is a command in the database. Two policies documented instead of four, and what is missing said as such rather than left out. Since nothing forces anybody to enrol, the invitation administrators and staff members get at login is described where a reader meets it, with what the two declining buttons remember and for how long. Two more entries from what shipped: a server clock moving backwards, which refuses every code as a replay until it catches up -- and it has its own way out, distinct from plain drift -- and the limits of a reset, which only ever goes downwards. The paragraph on clearing the super administrator no longer mentions being sent back to enrolment: no policy can require that in 1.3.0. It says how to turn the second factor off for everybody instead, which is what somebody reading that page at two in the morning is after.
trasher
force-pushed
the
feature/2factor
branch
from
September 18, 2026 21:13
cd3d5e2 to
3ab9140
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.