code icon indicating copy to clipboard operation
code copied to clipboard

Option to not require 2fa from a browser again for 30 days

Open MisterCheezeCake opened this issue 10 months ago • 0 comments

Please confirm the following.

  • [x] I checked the existing issues for duplicate feature requests
  • [x] I have checked that this feature request is not on our roadmap

What parts of Modrinth is your feature request related too?

Website

Is your suggested feature related to a problem? Please describe.

I have 2fa on my account, which I consider a must for anyone who uploads mods, lest we put our users at considerable security risk. Modrinth also sometimes signs me out of a session, which is of course to be expected, but every single time I sign in on a browser, even if it's the same exact locked secure device I signed in with a week ago, I need to input my 2fa code, which requires getting out my phone and is rather a hastle.

Describe the solution you'd like

Implement the feature, already found in many other sites, where when signing in with a 2fa code, you can opt to have the site not ask again on your browser for 30 days. (I believe this probably internally works with a token stored in a cookie, similar to how normal session tokens work but over a slightly longer span).

Describe alternatives you've considered

Living with having to pull out my phone every time I want to login to Modrinth, which seems to log me our rather frequently compared to other services such as GitHub. Having to do that's not the end of the world, but it's annoying to do every time, rather than only once a month or so on a device I know is secure and could be trusted to posses a longer living access token (which is really all a 2fa persistence token is, except it only authenticates through the 2fa layer).

Additional context

No response

MisterCheezeCake avatar Mar 13 '25 04:03 MisterCheezeCake