Skip to content

feat: expand 2FA support - #1254

Open
CosDiabos wants to merge 1 commit into
codeigniter4:developfrom
CosDiabos:feat/expand2FaSupport
Open

CosDiabos wants to merge 1 commit into
codeigniter4:developfrom
CosDiabos:feat/expand2FaSupport

Conversation

@CosDiabos

Copy link
Copy Markdown
Contributor

Although Shield currently offers 2FA, its support is somewhat limited. Like this discussion #1120, I also feel that it could benefit from a more robust system, like supporting multiple 2FA systems, allowing global/per user 2FA, or setting custom 2FA actions per user group, like suggested in discussions.

I would love to know what you think.

Description
This PR expands support of 2FA actions for Shield. It allows having multiple active 2FA methods, per-user or site-wide 2FA, per-group custom 2FA action, and a default. The settings $Mfa, $forceMfa, $actionsMfa, $defaultMfa and $matrixMfa are introduced to the Auth config file to control these settings. The per-user 2FA is achieved through a new column named mfa in the user table acting as a flag. The User Entity introduces the isMfaActive() :bool method for easy access to the property.

Within the Authenticators/Session.php:511, currently, the auth_action_message is being assigned the extra field directly. Expanding the 2FA actions, that extra field may be useful to store data related to the identity, so the ActionInterface introduces the getActionMessage() :string method to get this auth_action_message value from the action.

These changes introduce breaking changes to past versions.

Implements #1120

Checklist:

  • Securely signed commits
  • Component(s) with PHPDoc blocks, only if necessary or adds value
  • Unit testing, with >80% coverage
  • User guide updated
  • Conforms to style guide

@datamweb datamweb added breaking change Pull requests that may break existing functionalities enhancement New feature or request labels Feb 25, 2025
@datamweb

Copy link
Copy Markdown
Collaborator

Thank you for submitting PR.
To be honest, I’ve actually needed such features in several projects, but I’ve implemented them in a custom way using custom actions. In my opinion, Shield should have provided a simpler solution for setting these things up, but for some reason, it didn’t. Now, we are at a stage where I’m not eager to introduce a breaking change that could potentially affect many projects.

You can keep the PR open to gather feedback from the community, or it might be better to inform them on the forum or Slack.

@datamweb

Copy link
Copy Markdown
Collaborator

With all due respect, given that your PRs are quite large, I kindly suggest using the atomic commit approach. This will make the review process easier and faster for others. Smaller, more focused commits allow the team to review changes more efficiently.

Additionally, if possible, please consider writing your commit messages in a way that provides a clear and concise explanation of the changes.
https://www.conventionalcommits.org/en/v1.0.0/
https://gist.github.com/joshbuchea/6f47e86d2510bce28f8e7f42ae84c716

@michalsn

Copy link
Copy Markdown
Member

I'm afraid that a breaking change at this stage of the library (in v1) is not an option. We can improve the way we handle actions, but it must be an evolution, not a revolution.

@memleakd memleakd mentioned this pull request May 23, 2026
5 tasks done
@cloudrepublic-steve

Copy link
Copy Markdown

MFA options for Shield: four packages from Cloud Republic

Hi all,

Following the discussion on this PR and in #1120 about extending 2FA in Shield, I wanted to share some work that may help. Without touching Shield's core, we've built and released four MFA packages for Shield. They work with the existing Actions system, so there are no breaking changes.

Package What it does
shield-totp-mfa Authenticator-app MFA (Google Authenticator, Microsoft Authenticator, Authy, 1Password, etc.), with Actions, controllers and a route filter
shield-passkey-mfa Passkey (WebAuthn/FIDO2) MFA, with self-service add/rename/remove of multiple passkeys. It uses web-auth/webauthn-lib for the cryptography
shield-whatsapp-mfa A 6-digit one-time code sent over WhatsApp as a second factor, with self-service phone number verification
shield-mfa-dispatcher Shield's Config\Auth::$actions['login'] accepts only one class. The dispatcher is that one class, and it picks the right Action per user at request time, so different users can use different methods

The dispatcher covers a lot of what this PR is aiming for (multiple active MFA methods and per-user choice) without a schema change to the users table or any breaking API changes.

Details

  • MIT licensed
  • Tested on CodeIgniter 4.6 and 4.7, up to PHP 8.5
  • Installable via Composer under the cloudrepublic/ vendor namespace

Links

Feedback, issues and PRs are very welcome, especially from anyone with a use case the dispatcher doesn't cover yet. If there are gaps that would make more sense in Shield itself, I'd be happy to help work out a non-breaking way to do it.

Thanks!
Steve

@datamweb

Copy link
Copy Markdown
Collaborator

@cloudrepublic-steve Thank you for sharing the packages. If possible, please also share them in the Discussions section.

@cloudrepublic-steve

Copy link
Copy Markdown

@cloudrepublic-steve Thank you for sharing the packages. If possible, please also share them in the Discussions section.

Will do! I added a comment into the general CI forum but wasn't sure if that was the right place for it but there were a few other comments regarding Shield so posted it there anyway. I'll update the shield discussion topic now. Thanks

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking change Pull requests that may break existing functionalities enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants