Allow 2FA for SAML and LDAP users (#4000)

* inline totp image as data uri to prevent caching issues
* allow 2fa for ldap and saml users
* allow 2FA access for super admin to all profiles
This commit is contained in:
Kevin Papst
2023-05-01 08:28:35 +02:00
committed by GitHub
parent 01e26dca9e
commit 7112e932a2
6 changed files with 51 additions and 77 deletions

View File

@@ -3,12 +3,14 @@ scheb_two_factor:
security_tokens:
- Symfony\Component\Security\Core\Authentication\Token\UsernamePasswordToken
- Symfony\Component\Security\Http\Authenticator\Token\PostAuthenticationToken
- App\Saml\SamlToken
totp:
enabled: true
template: security/2fa.html.twig # Overwritten template
window: 1 # How many codes before/after the current one would be accepted as valid
# server_name: Server Name # Server name used in QR code
issuer: Kimai # Issuer name used in QR code
# parameters: # Additional parameters added in the QR code
# image: 'https://my-service/img/logo.png'
two_factor_condition: App\Security\TwoFactorCondition
# FIXME add backup codes - https://symfony.com/bundles/SchebTwoFactorBundle/current/backup_codes.html