Feature Request: 2 Factor Authentication

Hello everybody,

I had a question about a feature request regarding 2 Factor Authentication. An earlier topic 2 Factor Authentication was already closed so I took the liberty to open a new one.

Currently the login procedure is via Username and Password. I was wondering what would be needed to add and implement a 2FA feature into WebODM?

As you some of you may know I’m a big advocate for open source applications and communicate this to our clients as well. Some of these clients are (semi)government such as Water Authorities who use WebODM to map their drone-images. WebODM also fits very well in the mindset of the Dutch (Digital) Government as you can read here Kennisnetwerk Open Source Software (OSS)

2FA
However one of the functional requirements for (open source) web-applications, for this usergroup, is the option for 2FA.

Since I’m no programmer myself I was wondering what would be needed to implement this feature into WebODM? In budget, time and resources / capacity?

ChatGPT gave me the direction that the following repo could be implemented :wink: GitHub - jazzband/django-two-factor-auth: Complete Two-Factor Authentication for Django providing the easiest integration into most Django projects.

I can also imagine it would be a nice addional (security) layer in WebODM Lightning as well.

Thanks!

Mark

It’s something that could be added; probably not via the package you linked however, for two reasons. 1. Seems to be compatible with Django >= 4.x, whereas we are still on 2.x. 2. These packages (usually in my experience) seem nice at first, but often don’t integrate smoothly or provide too many / too little features. That said, there could be parts that can be re-used from the package.

I’m not sure about cost without taking a deeper look at requirements (e.g. is text message support needed, or Google Authenticator support is enough? What about YubiKey?), but probably 1-2 weeks of time.

Hi Piero,

Thanks for your answer.
The (Google/Microsoft) Authenticator implementation would be great.
The SMS verification isn’t recommended (at least in the Netherlands) for the possibility of SIM Swapping.

Best regards,

Mark

1 Like