- Issue created by @cmlara
- Status changed to Closed: works as designed
almost 2 years ago 9:27am 12 April 2023 - π΅πΉPortugal jcnventura
The module should cater for the 99%. For those 99% of uses, as seen by the fact that there's essentially a 1:1 install rate between ga_login and tfa in Drupal 8+, it is clear that the vast majority of users used the ga_login module.
The fact that these modules were in a separate module led to a few confused users raising support tickets for not understanding how the module worked.
Any user sufficiently advanced to want to use their own TOTP plugins should also know how to do the following two easy steps if the presence of the provided plugins is a nuisance:
- Add a line to their project's root composer.json to replace the undesired libraries
- Patch the module to disable the current plugins from being shown as options
- πΊπΈUnited States cmlara
Patch the module to disable the current plugins from being shown as options
As I'm sure you are aware as the modules maintainer, keeping a TFA module secure is not a simple task, it takes skill to do so, as such patching of security modules is generally not recommended, yes it can be done, however any reasonable security audit should be raising significant questions if it is.
The fact that these modules were in a separate module led to a few confused users raising support tickets for not understanding how the module worked.
Couldn't this be solved by adding UI "No Authentication modules detected, consider installing drupal/ga_login" (or whatever replacement module there is)
Add a line to their project's root composer.json to replace the undesired libraries
Not currently an option without also patching the module, since the plugins are always loaded by the UI, and do not use DI for the additional libraries. Addtionaly even if a generic OTP library existed and the plugins supported DI this would still require a library to be installed, even if its not used.
as seen by the fact that there's essentially a 1:1 install rate between ga_login and tfa in Drupal 8+
I will agree I would expect it to be common, making drupal/tfa require drupal/ga_login would actually be easier to replace as a contributing module could have a composer replace drupal/ga_login entry without requiring patching to TFA itself. As an added bonus this would also help limit potential SA notices scope to only their target audiance, no need to upgrade the full TFA module if its just a token module that isn't installed on a site. This is the concept of "small packages focus on limited tasks and use other packages to extend" similar to Drupal core.