<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Optional 2FA for proxy auth?]]></title><description><![CDATA[<p dir="auto">This isn't really a big deal, and I'd guess quite probably not really possible either but...</p>
<p dir="auto">I've got 2FA set-up on my account because I don't want anyone gaining access to Cloudron admin.</p>
<p dir="auto">But for nearly all the apps that have proxy auth added, 2FA is overkill and it mildly frustrates me that I have to get my phone out to generate a 2FA code using my FreeOTP+ authenticator app.</p>
<p dir="auto">I'd love there to be a way where 2FA is enforced for logging into Cloudron dashboard, but not when logging into (at least some) apps.</p>
<p dir="auto">Like I said, this isn't really a big deal, and I'd guess quite probably not really possible either but figured I'd mention it anyways <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/topic/10384/optional-2fa-for-proxy-auth</link><generator>RSS for Node</generator><lastBuildDate>Tue, 09 Jun 2026 14:29:59 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/10384.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 09 Nov 2023 12:56:07 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Optional 2FA for proxy auth? on Thu, 09 Nov 2023 13:06:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/77081">Optional 2FA for proxy auth?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> proxyAuth will move to OIDC based login very soon. Once that is done, hopefully you don't have to deal with this much (because it will automatically login for other apps).</p>
</blockquote>
<p dir="auto">Ah yes, I figured that might soon be the case. Excellent, I think that'll basically solve it <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/77081">Optional 2FA for proxy auth?</a>:</p>
<blockquote>
<p dir="auto">On a general note, it's not possible to disable 2FA since this will be a security hole which bypasses 2FA <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title="🙂" alt="🙂" /> As in, one can keep trying username/password combinations without a 2FA now and know if it's valid or not.</p>
</blockquote>
<p dir="auto">Figured there'd be a good reason not to do it <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/post/77082</link><guid isPermaLink="true">https://forum.cloudron.io/post/77082</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Thu, 09 Nov 2023 13:06:18 GMT</pubDate></item><item><title><![CDATA[Reply to Optional 2FA for proxy auth? on Thu, 09 Nov 2023 13:04:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> proxyAuth will move to OIDC based login very soon. Once that is done, hopefully you don't have to deal with this much (because it will automatically login for other apps).</p>
<p dir="auto">On a general note, it's not possible to disable 2FA since this will be a security hole which bypasses 2FA <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /> As in, one can keep trying username/password combinations without a 2FA now and know if it's valid or not.</p>
]]></description><link>https://forum.cloudron.io/post/77081</link><guid isPermaLink="true">https://forum.cloudron.io/post/77081</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 09 Nov 2023 13:04:10 GMT</pubDate></item></channel></rss>