Skip to content

Add MFA with Django-AllAuth - #48

Open
rechner wants to merge 11 commits into
devfrom
rechner/django-allauth-2fa
Open

rechner wants to merge 11 commits into
devfrom
rechner/django-allauth-2fa

Conversation

@rechner

@rechner rechner commented Sep 20, 2026

Copy link
Copy Markdown
Member

Closes #45.

Uses Django-allauth to add MFA via TOTP, Passkey, and backup codes.

  • Add MFA policy enforcement for admin users with config toggle
  • Integrate django-allauth for headless authentication with JWT tokens
  • Create MFA setup allowed paths for first enrollment
  • Update frontend authentication flow with MFA-aware login component
  • Enable passkey-based login with MFA as optional verification layer

Also accepts legacy session JWTs to minimize deployment disruption.

- Add MFA policy enforcement for admin users with config toggle
- Integrate django-allauth for headless authentication with JWT tokens
- TOTP, WebAuthn, and recovery code MFA methods
- Create MFA setup allowed paths for first enrollment
- Update frontend authentication flow with MFA-aware login component
- Enable passkey-based login with MFA as optional verification layer
@github-actions

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-rechner-django-allauth-2fa. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

- Prevent admin users from bypassing MFA through legacy login endpoint during SSO handoff
@github-actions

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-rechner-django-allauth-2fa. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

@github-actions

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-rechner-django-allauth-2fa. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

- Fix `_session_for_token()` to support both raw session token and encrypted AllAuth JWT claim
@github-actions

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-rechner-django-allauth-2fa. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

@github-actions

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-rechner-django-allauth-2fa. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

@github-actions

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-rechner-django-allauth-2fa. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-rechner-django-allauth-2fa. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

@rechner rechner added the enhancement New feature or request label Sep 25, 2026
@taylordotfish taylordotfish self-assigned this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add 2FA and Passkey support

2 participants