Added secuirty 2FA for users
This commit is contained in:
Vendored
+27
@@ -15,6 +15,17 @@ export type IpalOptions = {
|
||||
* (admin > editor > user) into the client's auth collection.
|
||||
*/
|
||||
access?: AccessOption;
|
||||
/**
|
||||
* Custom admin panel route, e.g. '/its' instead of the default '/admin'.
|
||||
* The plugin sets config.routes.admin. IMPORTANT: this alone isn't enough —
|
||||
* the project must ALSO move its panel folder to match:
|
||||
* app/(payload)/its/[[...segments]]/page.tsx (and the not-found). The plugin
|
||||
* can't create files in the project's app/. See docs/security.md.
|
||||
*
|
||||
* This is obscurity, not security: it hides the panel from dumb bots scanning
|
||||
* /admin, but real protection is strong auth + 2FA + rate limiting.
|
||||
*/
|
||||
adminRoute?: string;
|
||||
/**
|
||||
* Collections whose entries live under an archive page — blog posts, case
|
||||
* studies, anything with a listing. Adds an "archive page" assignment per
|
||||
@@ -45,4 +56,20 @@ export type IpalOptions = {
|
||||
seo?: SeoOption;
|
||||
/** Additional fields injected into SiteSettings global */
|
||||
siteSettingsFields?: Field[];
|
||||
/**
|
||||
* Two-factor authentication (TOTP), ENFORCED for every user. Wires
|
||||
* @clocklimited/payload-2fa with forceSetup — no per-project opt-out. Every
|
||||
* user must configure an authenticator app after login; TOTP is checked before
|
||||
* data access (not just the admin UI). Requires the peer dep installed and an
|
||||
* issuer name (shown in the authenticator app).
|
||||
*
|
||||
* Pass `false` ONLY for a project that genuinely can't use 2FA (rare, discouraged)
|
||||
* — default is enforced. See docs/security.md.
|
||||
*/
|
||||
twoFactor?: {
|
||||
/** Auth collection slug. Defaults to 'users'. */
|
||||
collectionSlug?: string;
|
||||
/** Name shown in the authenticator app (e.g. company/site name). */
|
||||
issuer: string;
|
||||
} | false;
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user