twofactorauth
twofactorauth copied to clipboard
Update Bendigo Bank
According to the original PR #4718, the "security token" is only used for authorization, but not authentication. Has anything changed in this regard?
The TOTP provided by the Security Token (Symantec VIP) may be configured by the user to be required at login in addition to User ID and Password. The Security Token is also used for step-up authentication commensurate to sensitivity of transaction. However having reviewed the PR https://github.com/2factorauth/twofactorauth/pull/2973 I now understand that the 2factorauth project defines step-up authentication as a form of authorisation. Hopefully this definition will be amended. Irrespective of the step-up authentication definition, does configurable (optional) enforcement of the Security Token at login meet guidelines?
As the requested changes haven't been resolved yet I'm going to label this PR as inactive. Unless there's activity within the next week I'll close the PR.
Closing due to inactivity.