mirror of
				https://github.com/lingble/chatwoot.git
				synced 2025-10-31 02:57:57 +00:00 
			
		
		
		
	 4014a846f0
			
		
	
	4014a846f0
	
	
	
		
			
			FE support for https://github.com/chatwoot/chatwoot/pull/12290 ## Linear: - https://github.com/chatwoot/chatwoot/issues/486 ## Description This PR implements Multi-Factor Authentication (MFA) support for user accounts, enhancing security by requiring a second form of verification during login. The feature adds TOTP (Time-based One-Time Password) authentication with QR code generation and backup codes for account recovery. ## Type of change - [ ] New feature (non-breaking change which adds functionality) ## How Has This Been Tested? - Added comprehensive RSpec tests for MFA controller functionality - Tested MFA setup flow with QR code generation - Verified OTP validation and backup code generation - Tested login flow with MFA enabled/disabled ## Checklist: - [ ] My code follows the style guidelines of this project - [ ] I have performed a self-review of my code - [ ] I have commented on my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation - [ ] My changes generate no new warnings - [ ] I have added tests that prove my fix is effective or that my feature works - [ ] New and existing unit tests pass locally with my changes - [ ] Any dependent changes have been merged and published in downstream modules --------- Co-authored-by: Pranav <pranav@chatwoot.com> Co-authored-by: iamsivin <iamsivin@gmail.com> Co-authored-by: Sivin Varghese <64252451+iamsivin@users.noreply.github.com> Co-authored-by: Muhsin Keloth <muhsinkeramam@gmail.com> Co-authored-by: Sojan Jose <sojan@pepalo.com>
		
			
				
	
	
		
			29 lines
		
	
	
		
			584 B
		
	
	
	
		
			JavaScript
		
	
	
	
	
	
			
		
		
	
	
			29 lines
		
	
	
		
			584 B
		
	
	
	
		
			JavaScript
		
	
	
	
	
	
| /* global axios */
 | |
| import ApiClient from './ApiClient';
 | |
| 
 | |
| class MfaAPI extends ApiClient {
 | |
|   constructor() {
 | |
|     super('profile/mfa', { accountScoped: false });
 | |
|   }
 | |
| 
 | |
|   enable() {
 | |
|     return axios.post(`${this.url}`);
 | |
|   }
 | |
| 
 | |
|   verify(otpCode) {
 | |
|     return axios.post(`${this.url}/verify`, { otp_code: otpCode });
 | |
|   }
 | |
| 
 | |
|   disable(password, otpCode) {
 | |
|     return axios.delete(this.url, {
 | |
|       data: { password, otp_code: otpCode },
 | |
|     });
 | |
|   }
 | |
| 
 | |
|   regenerateBackupCodes(otpCode) {
 | |
|     return axios.post(`${this.url}/backup_codes`, { otp_code: otpCode });
 | |
|   }
 | |
| }
 | |
| 
 | |
| export default new MfaAPI();
 |