We should run through stuff that instance admins can do and make sure we're doing hisec checks.
Description
Description
Revisions and Commits
Revisions and Commits
Restricted Differential Revision | Restricted Diffusion Commit | ||
rP Phabricator | |||
D11803 | rP7f1914540f99 Phortune - require high security sessions for subscription edits |
Event Timeline
Comment Actions
For now, I think this is basically just:
- create an instance;
- invite members to an instance;
- edit subscription details in Phortune (particularly, enabling autopay).
We should have a hisec check on those things. We don't need to actually require that users set up two-factor auth.
Comment Actions
Notably, restarting daemons doesn't need a check, and none of the admin/management options have security implications.