Skip to main content

Documentation

No results found.
Features

Two-Factor Authentication

WebProCMS includes two-factor authentication (2FA) for the dashboard as a free, built-in feature — no add-on, no paid tier, no configuration required to turn it on. Every dashboard user can enable an authenticator-app second factor on their...

WebProCMS includes two-factor authentication (2FA) for the dashboard as a free, built-in feature — no add-on, no paid tier, no configuration required to turn it on. Every dashboard user can enable an authenticator-app second factor on their own account whenever they want. It is optional per user: the CMS never forces it, so non-technical clients are never locked behind a setup step they don't understand, while security-conscious admins can switch it on in seconds.


What it is

2FA adds a second step to dashboard login. After entering their password, the user is prompted for a rotating 6-digit code from an authenticator app on their phone (Google Authenticator, Authy, 1Password, Microsoft Authenticator, or any TOTP-compatible app). Because the code lives on a device the user physically holds, an attacker who only has the password — from a reused-password breach, a phishing page, or a keylogger — still can't get in.

It is built on Laravel Fortify's TOTP implementation, the same standard (RFC 6238) used across the industry.

Why it's the strong option

A second factor only matters if it lives outside the user's email. Email-based "2FA" (a code or magic link sent to the inbox) doesn't raise security at all, because the password-reset flow already emails the inbox — so control of the email is control of the account either way.

Authenticator-app 2FA is different: it survives an email compromise. An attacker can reset the password through the inbox all day and still be stopped at the 6-digit prompt, because the code comes from the user's phone, not their email. That's the whole point, and it's why WebProCMS ships TOTP rather than email codes.

Turning it on (per user)

Each user manages their own 2FA from the account menu (top-right) → Settings → Two-Factor Auth:

  1. Click Enable 2FA.
  2. Scan the QR code with an authenticator app (or copy the setup key in by hand).
  3. Enter the 6-digit code the app generates to confirm.
  4. Save the recovery codes that appear.

From the next login on, the dashboard asks for a code after the password.

Disabling is one click on the same page.

Recovery codes (don't get locked out)

When 2FA is enabled, the CMS generates a set of one-time recovery codes. These are shown once at setup and can be viewed/regenerated from the Two-Factor Auth settings page. If the user loses their phone, any one recovery code gets them past the login prompt so they can re-enroll a new device.

Recovery codes are stored hashed and are never emailed — keeping the second factor independent of the inbox, which is what makes it secure. Users should save them in a password manager or print them.

Admin reset (the lockout safety net)

Because 2FA is self-served and optional, sooner or later a user will replace their phone without saving their recovery codes and lock themselves out. WebProCMS handles this without a developer or a database edit:

On Dashboard → Users, the ⋯ menu → Reset 2FA clears two-factor for a locked-out user so they can re-enroll from their own settings. The control:

  • only appears for users who actually have 2FA enabled,
  • is governed by the same role rules as editing or deleting a user — you can only reset accounts at or below your own role,
  • removes the secret and recovery codes so the next login is password-only until the user sets 2FA up again.

This means an account owner or admin can always recover a stranded teammate or client in a couple of clicks.

Login throttling

The two-factor challenge and the login form are both rate-limited (5 attempts per minute, keyed to the account and IP) so the second factor can't be brute-forced.

Summary

Capability Included
Authenticator-app (TOTP) 2FA for the dashboard ✅ Free, built-in
Optional per user (never forced) ✅
QR-code + manual-key enrollment ✅
One-time recovery codes ✅
Admin "Reset 2FA" for locked-out users ✅
Rate-limited login + challenge ✅
Cost / add-on required None