2
2FA for web extension
Source: dani-garcia/vaultwarden#4746 · opened by @Unlisted1723
Hello,
I was wondering if it would be possible to require 2FA every time you want to unlock your vault with the web extension. Currently, you are asked for 2FA only on the first connection, but never after. So what is the purpose of having 2FA if you use it only once?
I noticed that you can set the session timeout to disconnect your account. However, this option works only if the user intentionally uses it and agrees to re-enter their email. Unfortunately, many of my colleagues will never do so.
So my question is: will there be an option to use 2FA when unlocking your vault? Or an option in the admin panel to force the logout after session timeout?
Best regards.
I was wondering if it would be possible to require 2FA every time you want to unlock your vault with the web extension. Currently, you are asked for 2FA only on the first connection, but never after. So what is the purpose of having 2FA if you use it only once?
I noticed that you can set the session timeout to disconnect your account. However, this option works only if the user intentionally uses it and agrees to re-enter their email. Unfortunately, many of my colleagues will never do so.
So my question is: will there be an option to use 2FA when unlocking your vault? Or an option in the admin panel to force the logout after session timeout?
Best regards.
No pledges yet. Be the first to back this.
Comments
Similar requests
Browser extension API authentication, without 2FA
1 vote · 0 comments
Additional configuration for hardening 2FA
2 votes · 0 comments
Disable 2FA email setup button if email 2FA is disabled in admin settings
1 vote · 0 comments
Default 2FA email for new users invited to organizations with 2FA-policy enabled
11 votes · 0 comments
Show notification and force if 2FA is required when first login
1 vote · 0 comments
No comments yet.