View Issue Details

IDProjectCategoryView StatusLast Update
0002836Composrcorepublic2016-10-11 20:33
ReporterChris GrahamAssigned ToChris Graham 
SeverityFeature-request 
Status resolvedResolutionfixed 
Product Version 
Fixed in Version 
Summary0002836: 2-factor authentication for maintenance scripts
DescriptionIf:
a) 2-factor authentication (IP verify by email) has been turned on for any administrator group
b) a new config option called something like "Auto-maintained 2-factor authentication for maintenance scripts" is enabled
c) .htaccess is writable

(If 'c' is not true then the 'b' option doesn't appear in the UI)

Then whenever an IP verify is done by an administrator the .htaccess is updated to only allow access by that administrator, and other administor-verified-IPs to the maintenance scripts.

The tut_security tutorial would need updating to reference this option, as currently it just shows manual code to add.
TagsType: Security
Time estimation (hours)3
Sponsorship open

Activities

Chris Graham

2016-10-04 21:43

administrator   ~0004369

Remember to include in the new security level in the Setup Wizard

Issue History

Date Modified Username Field Change
2016-09-20 18:29 Chris Graham New Issue
2016-09-20 18:29 Chris Graham Tag Attached: Type: Security
2016-10-04 21:43 Chris Graham Note Added: 0004369
2016-10-11 20:33 Chris Graham Status non-assigned => resolved
2016-10-11 20:33 Chris Graham Resolution open => fixed
2016-10-11 20:33 Chris Graham Assigned To => Chris Graham