Skip to content

Conversation

@LazyCat2
Copy link

@LazyCat2 LazyCat2 commented Mar 3, 2025

No description provided.

Signed-off-by: LazyCat2 <68156188+LazyCat2@users.noreply.github.com>
MCausc78 added a commit to MCausc78/stoat.py that referenced this pull request Mar 3, 2025
Copy link

@StupidRepo StupidRepo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think forcing the user to have 2FA before being able to transfer servers would be a good idea instead of suggesting that any account can transfer a server. 👍🏼

@insertish
Copy link
Member

The way the 2FA flow works currently means it'll fallback to password auth if no methods are available, if we could use & specify that then this would be perfect. This would protect against situations where someone would somehow get the authentication token, but would be unlikely to have the password for example.

Signed-off-by: LazyCat2 <68156188+LazyCat2@users.noreply.github.com>
@StupidRepo
Copy link

StupidRepo commented Mar 31, 2025

This would protect against situations where someone would somehow get the authentication token, but would be unlikely to have the password for example.

Yeah, me and LazyCat talked about that on the Revolt Development server/original PR a while ago lol.

@insertish insertish added the Final Comment Period The RFC is in the final comment period label Apr 2, 2025
@insertish
Copy link
Member

I don't think there are any substantial blockers that would mean we need to delay the merge here?
I would just skip procedure, I'll let the team chime in.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Final Comment Period The RFC is in the final comment period

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants