feat: Add two-factor authentication via TOTP

Adds TOTP setup with QR code, login challenge, recovery codes and
trusted devices that let a browser skip the second factor for 30
days. Admins can reset another user's second factor by confirming
with their own password.
This commit is contained in:
Daniel Hiller
2026-08-07 20:11:55 +02:00
parent 36aa732fec
commit 2e4904f77d
74 changed files with 4173 additions and 4 deletions
@@ -98,6 +98,7 @@
* type: string
* enum:
* - Terms acceptance required
* - TOTP verification required
* - Admin login required to initialize instance
* description: Specific error message
* example: Terms acceptance required
@@ -155,6 +156,9 @@ module.exports = {
termsAcceptanceRequired: {
responseType: 'forbidden',
},
totpVerificationRequired: {
responseType: 'forbidden',
},
adminLoginRequiredToInitializeInstance: {
responseType: 'forbidden',
},
@@ -197,6 +201,9 @@ module.exports = {
}))
.intercept('termsAcceptanceRequired', (error) => ({
termsAcceptanceRequired: error.raw,
}))
.intercept('totpVerificationRequired', (error) => ({
totpVerificationRequired: error.raw,
}));
},
};