[PR #26112] feat: Add Multi-Factor Authentication (MFA) support #31339

Closed
opened 2026-02-21 20:49:16 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/26112

State: closed
Merged: No


This commit introduces comprehensive MFA support using TOTP (Time-based One-Time Password) authentication.

Backend Changes:

  • Added AccountMFASettings model to store MFA configuration
  • Created MFAService for TOTP operations (setup, verification, backup codes)
  • Added MFA API endpoints for setup, verification, and management
  • Enhanced login flow to check MFA requirements
  • Added MFA-specific error handling classes

Frontend Changes:

  • Created MFA setup and verification UI components
  • Added MFA status display in account settings
  • Integrated MFA verification into login flow
  • Added QR code generation for authenticator app setup
  • Included backup codes display and management

Features:

  • TOTP-based authentication using standard authenticator apps
  • Backup codes for account recovery
  • User-friendly setup flow with QR code
  • Secure token verification with 30-second time window
  • Comprehensive error handling and validation

Security:

  • Secrets encrypted before storage
  • Rate limiting on verification attempts
  • Secure random backup code generation
  • Time-based token validation with drift tolerance

Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/26112 **State:** closed **Merged:** No --- This commit introduces comprehensive MFA support using TOTP (Time-based One-Time Password) authentication. ## Backend Changes: - Added AccountMFASettings model to store MFA configuration - Created MFAService for TOTP operations (setup, verification, backup codes) - Added MFA API endpoints for setup, verification, and management - Enhanced login flow to check MFA requirements - Added MFA-specific error handling classes ## Frontend Changes: - Created MFA setup and verification UI components - Added MFA status display in account settings - Integrated MFA verification into login flow - Added QR code generation for authenticator app setup - Included backup codes display and management ## Features: - TOTP-based authentication using standard authenticator apps - Backup codes for account recovery - User-friendly setup flow with QR code - Secure token verification with 30-second time window - Comprehensive error handling and validation ## Security: - Secrets encrypted before storage - Rate limiting on verification attempts - Secure random backup code generation - Time-based token validation with drift tolerance > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:49:16 -05:00
yindo closed this issue 2026-02-21 20:49:16 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#31339