Email-based authentication option
backlog
J
Jamie Morris
backlog
J
Jamie Morris
Merged in a post:
Verify Access to Email to Log Into Displayr account
A
Adam Gross
As a dashbaord publisher, it is simple enough to invite a group of end-clients to have access to a published dashboard.
Right now, Displayr does not require email access verification to log into Displayr. So, we imagine a scenario where an employee is terminated from a company, but this employee still has access to the Displayr dashboard because there is currently no mechanism to confirm email access when logging in.
This can be a security problem.
The proposal would be to require that the user authenticates their email access by entering in a code sent to the email address linked to the user account (or clicks a link sent to the email address).
A conceivable workaround would be to manually reset the users password every so often to confirm that the users have access to the associated emails.