Files
accounted/lib/auth/mfa.ts
T
Jakob Wennberg 928a145f9a feat: upgrade auth to email+password with optional TOTP MFA
- Replace magic-link-only login with email+password (primary) and magic link (toggle)
- Add registration page with strong password validation
- Add MFA enrollment (/mfa/enroll) with QR code and manual secret
- Add MFA verification (/mfa/verify) with 6-digit TOTP input
- Add password reset flow (/reset-password)
- Add middleware MFA enforcement gated by NEXT_PUBLIC_REQUIRE_MFA env var
- Self-hosted deployments (NEXT_PUBLIC_SELF_HOSTED=true) skip MFA entirely
- Add Security tab in Settings for password change and MFA management
- Add requireAuth() API route helper with MFA check
- Update CLAUDE.md with Authentication section and env var docs
- Update Dockerfile and docker-entrypoint.sh for new env var placeholders

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 10:17:49 +01:00

12 lines
379 B
TypeScript

/**
* MFA (Multi-Factor Authentication) helpers.
*
* MFA is only required on the hosted version, never for self-hosted deployments.
* Enforcement is application-side (middleware + API routes), not RLS.
*/
export function isMfaRequired(): boolean {
if (process.env.NEXT_PUBLIC_SELF_HOSTED === 'true') return false
return process.env.NEXT_PUBLIC_REQUIRE_MFA === 'true'
}