FeatureFuel
1

[Feature Request] Bypass 2fa prompt for SSO logins

Source: paperless-ngx/paperless-ngx#14097 · opened by @penguintamer
Description For users who have Paperless accounts with TOTP 2fa/mfa, logging in with the configured SSO (OIDC) provider returns them to the TOTP entry page as if they had successfully authenticated with their username and password, rather than being directly logged in, as most services with external authentication do. Since my IdP already enforces MFA, this means users have to enter two different TOTP codes when signing into Paperless-ngx. I don't want to disable local passwords / TOTP entirely, because it's necessary when there's an issue/outage with the OIDC provider. Steps to reproduce: 1. Set up a Paperless-ngx server with an OIDC authentication provider 2. Log in with an OIDC user account 3. Add a password and authenticator to the account 4. Log out and back in with that user via OIDC 5. User is presented with the page to enter TOTP authenticator Expected: OIDC handles authentication entirely, and user is not prompted for additional authenticatio…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests