If you enable Two Factor Authentication
on the site, then you will have to enter a temporary code from the application every time you enter the site. This is very inconvenient, especially when you visit the site only from your computer and publish news on the site every day.
I suggest adding an option that will allow you to remember
the trusted device to log in
and not have to re-enter the temporary code from the application.
For example: When I first go to the site from my home computer, I can check the "remember this device" checkbox and then when I log in again from this device I will not have to re-enter the temporary code from the application.
Do not show the timecode input field until the user clicks the login button.
After the user has pressed the log in
button, show him the field for entering the time code from the application.
This can be very helpful if I go back to the site from a trusted device, or if I am a user who has not yet enabled Two Factor Authentication
in my profile, and therefore should not see the field for entering the time code.
Additional security option (can be enabled in user settings):
When a user logs in from a new device for the first time (for example, after purchasing a new smartphone), send them an email with a notification about a new login from a new device and a link "It wasn't me" so that the user can reset the password by clicking on this link, if it was not they but someone else who logged in from the new device.
If this login was made by the user, then they don't need to do anything when they receive the email, and when they first log in to the website, they can click the "add this device to trusted" button.
If the user clicked the "add this device to trusted" button when logging in from a new device, then when they log in again from this device, they will not receive an email notification that they logged in from this device, because this device will be in their list of trusted devices
.
The user will always be able to view all trusted devices
in their user settings (there will be a list of devices with titles - PC models, smartphones, etc. with the IP address of the first login from this device and the date of the first login from this device).
I've seen this kind of login method on all popular sites. I've seen this on social media, online shopping and many other sites. I don't see the point of entering this code every time if I visit the site only from the same device. @joomla is not an application of my bank.
I only want to use the timecode entry on the devices from which I log in for the first time. I mean, there should be an option so that you can "remember the trusted device" and the user can decide for himself whether he will re-enter the code when entering from this device or whether he wants to remember this device as a trusted one.
Now Joomla has only 2 options:
Two Factor Authentication
Two Factor Authentication
I suggest a third option:
Labels |
Added:
?
|
Labels |
Added:
?
No Code Attached Yet
Removed: ? |
Title |
|
Additional security option (can be enabled in user settings):
When a user logs in from a new device for the first time (for example, after purchasing a new smartphone), send them an email with a notification about a new login from a new device and a link "It wasn't me" so that the user can reset the password by clicking on this link, if it was not they but someone else who logged in from the new device.
If this login was made by the user, then they don't need to do anything when they receive the email, and when they first log in to the website, they can click the "add this device to trusted" button.
If the user clicked the "add this device to trusted" button when logging in from a new device, then when they log in again from this device, they will not receive an email notification that they logged in from this device, because this device will be in their list of trusted devices
.
The user will always be able to view all trusted devices
in their user settings (there will be a list of devices with titles - PC models, smartphones, etc. with the IP address of the first login from this device and the date of the first login from this device).
Yes good suggestions I support them.
This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/30630.