Kural #0
AKTİF KULLANIMDA
Two-Factor Authentication (2FA) Setup Guide
Genel Bakış & Tanım
The HEIRA two-factor authentication (2FA) system protects your account not only with your password, but also with a 6-digit dynamic code from Microsoft or Google Authenticator. The secret key is stored AES-256-CBC encrypted, recovery codes are one-time-use and known only to you. Critical operations (disabling 2FA, regenerating backup codes) require an extra Sudo Mode password verification.
Adım Adım Kullanım & İşleyiş Mantığı
1
Start 2FA Setup
Go to the Security page → click "Start 2FA Setup". The system automatically generates a 32-char Base32 secret key and stores it AES-256-CBC encrypted.
2
Scan QR Code
Scan the QR code shown on screen with Microsoft Authenticator using "Add Account → Work or School → Scan QR Code". If you cannot scan, you can manually enter the Secret Key text shown.
3
Verify the Code
Get the 6-digit code from your Authenticator app (refreshes every 30 seconds). Enter it in the "Verify Code" field and press "Activate 2FA". ±60-second clock drift tolerance is applied.
4
Save Recovery Codes
When 2FA activates, the system generates 10 single-use recovery codes. Write them down somewhere safe — you can use them to access your account if you lose your phone.
5
Login Flow
From now on, after entering your password you will be asked for the 6-digit code from your Authenticator app. Select "Remember this device for 30 days" on trusted devices to skip the prompt.
6
Disabling 2FA (Sudo Mode)
To disable 2FA, a Sudo Mode password verification is required first. Enter your password → after verification, the "Completely Disable 2FA" button becomes active for 10 minutes. A security alert email is automatically sent after disabling.
7
Regenerate Recovery Codes
Use the "Generate New Recovery Codes" button on the security page. This also requires Sudo Mode verification and sends an email notification.
8
Trusted Device Management
You can add trusted devices via the "Remember this device for 30 days" option at login. From the security page you can list trusted devices and remove them with "Revoke". This also requires Sudo Mode.
9
Clock Drift Warning
If your device clock drifts more than 60 seconds from internet time, you will see a yellow warning after login. Enable "Date & Time → Set Automatically" on your device.
10
Security Emails
You will receive automatic security alert emails when 2FA is enabled, disabled, backup codes are regenerated, or your account is locked after 5 failed attempts. If you did not request this email, change your password immediately.
Teknik Mimari & Entegrasyon Kodları
SYSTEM_KEY: two_factor_guide.json
Files: user/security.php (user 2FA management), admin/2fa_settings.php (admin panel), includes/two_factor.php (core engine), login.php (verification flow). DB Tables: users (two_factor_secret AES-256 encrypted, two_factor_enabled, two_factor_required), user_2fa_backup_codes, user_2fa_trusted_devices, user_2fa_attempts, user_2fa_logs, user_2fa_sudo_sessions. Encryption: AES-256-CBC, key in .heira_2fa.key. Algorithm: RFC 6238 TOTP, 30s, SHA1 HMAC. Clock tolerance: ±2 steps (±60 seconds).
Servis Sağlık Durumu & Test Sonuçları
QR kurulum testi
Çapraz Platform Uyumlu
TOTP doğrulama testi
Çapraz Platform Uyumlu
AES şifreleme testi
Çapraz Platform Uyumlu
Kurtarma kodu testi
Çapraz Platform Uyumlu
Sudo Modu testi
Çapraz Platform Uyumlu
Saat kayması testi
Çapraz Platform Uyumlu
Güvenlik e-posta testi
Çapraz Platform Uyumlu
Rate limit testi
Çapraz Platform Uyumlu
Güvenilir cihaz testi
Çapraz Platform Uyumlu