CW-021 · Two-factor enrolment on mobile
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 65/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- flutter
- Domain
- authentication, mobile, security
Research direction
Start in mobile/lib/features/auth/ and trace the existing second-factor code and recovery-code flows, including the settings.security.requireMfa path. Define the enrolment entry point and verify the acceptance cases: a phone-only employee can enrol and sign in, and recovery codes are shown once with a way to save them.
Written by the indexing model from the issue text.
Description
Priority P2 · Area mobile · Estimate M · Phase 4
The app can complete a second factor — it shows a code field and accepts a generated or recovery code — but it cannot enrol one. Scanning a QR code with the phone that is displaying it does not work, so an account required to have a second factor is currently told to enrol in the web console first.
That is fine while the requirement only reaches privileged console roles. An organisation that turns on settings.security.requireMfa for everyone leaves its field staff unable to set themselves up from the only device they have.
Scope
Enrolment without a camera round-trip: show the secret, offer a "copy to clipboard" and a deep link that hands the otpauth:// URI straight to an authenticator app on the same device, then confirm with a code.
Acceptance
An employee with no console access can enrol and sign in using only the phone, and the recovery codes are shown once with a way to save them.
Files mobile/lib/features/auth/
Tracked in docs/backlog.md.
- Dominant language
- TypeScript
- Stars
- 0
- Forks
- 0
- Avg merge
- 37m
- Merged PRs (30d)
- 1
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from SuruchBoss/Cwork
-
documentation good first issue P3 phase-E
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
SuruchBoss/Cwork#50 ·
-
good first issue mobile P2
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
SuruchBoss/Cwork#11 ·
-
P1 payroll phase-3
Difficulty 5/5 Over a week Newbie friendliness 30/100
SuruchBoss/Cwork#59 ·
-
P2 phase-3
Difficulty 5/5 Over a week Newbie friendliness 45/100
SuruchBoss/Cwork#58 ·
-
P3 project
Difficulty 3/5 1-2 days Newbie friendliness 76/100
SuruchBoss/Cwork#56 ·
All issues in SuruchBoss/Cwork
Similar issues
-
refactor
Difficulty 2/5 Half a day Newbie friendliness 84/100
Maintainers usually reply within 5 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
OHDSI/Data2Evidence#3450 ·
Maintainers usually reply within 2 days
-
e2e-failure ready-to-code
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
redhat-developer/rhdh-plugin-export-overlays#4011 · 1 comment ·
Maintainers usually reply within 1 day
-
automation missing-model model-sync provider:ofox
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
anomalyco/models.dev#8421 ·
Maintainers usually reply within 1 day
-
SlackAdapter and TelegramAdapter are not assignable to Adapter under exactOptionalPropertyTypesOpen
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day