GlobaLeaks icon indicating copy to clipboard operation
GlobaLeaks copied to clipboard

Notify user by mail when an admin resets the users 2FA

Open aetdr opened this issue 2 years ago • 1 comments

Hi @evilaliv3

When an admin resets 2FA registration for a specific user (clicking on the big red button) the user does not get notified. It would be valuable to inform the user by mail about the action in order to reestablish 2FA as quickly as possible.

aetdr avatar Jul 06 '22 09:07 aetdr

Thank you for this suggestion @aetdr

This would be definitely a good improvement. If you could please please feel free to provide a patch for this addition.

I would consider valuable as well to track enabling/disabling of 2FA in in the audit log and to make it possible for users to read the audit log that pertain their own account.

All these considerations are probably interesting also for operations of password change or email change where the user should be probably notified.

evilaliv3 avatar Jul 06 '22 10:07 evilaliv3