Added secuirty 2FA for users

This commit is contained in:
2026-09-28 15:49:36 +02:00
parent 7cef95225a
commit 060a61fd41
10 changed files with 453 additions and 86 deletions
+27
View File
@@ -15,6 +15,17 @@ export type IpalOptions = {
* (admin > editor > user) into the client's auth collection.
*/
access?: AccessOption;
/**
* Custom admin panel route, e.g. '/its' instead of the default '/admin'.
* The plugin sets config.routes.admin. IMPORTANT: this alone isn't enough —
* the project must ALSO move its panel folder to match:
* app/(payload)/its/[[...segments]]/page.tsx (and the not-found). The plugin
* can't create files in the project's app/. See docs/security.md.
*
* This is obscurity, not security: it hides the panel from dumb bots scanning
* /admin, but real protection is strong auth + 2FA + rate limiting.
*/
adminRoute?: string;
/**
* Collections whose entries live under an archive page — blog posts, case
* studies, anything with a listing. Adds an "archive page" assignment per
@@ -45,4 +56,20 @@ export type IpalOptions = {
seo?: SeoOption;
/** Additional fields injected into SiteSettings global */
siteSettingsFields?: Field[];
/**
* Two-factor authentication (TOTP), ENFORCED for every user. Wires
* @clocklimited/payload-2fa with forceSetup — no per-project opt-out. Every
* user must configure an authenticator app after login; TOTP is checked before
* data access (not just the admin UI). Requires the peer dep installed and an
* issuer name (shown in the authenticator app).
*
* Pass `false` ONLY for a project that genuinely can't use 2FA (rare, discouraged)
* — default is enforced. See docs/security.md.
*/
twoFactor?: {
/** Auth collection slug. Defaults to 'users'. */
collectionSlug?: string;
/** Name shown in the authenticator app (e.g. company/site name). */
issuer: string;
} | false;
};