You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Following a discussion on the OAuth2 app, we should make the regular user password not to be allowed as a way to authenticate with ownCloud when enforced. Using, for non-compatible clients (e.g. DAV, WND...), an application password instead.
@DeepDiver1975 mentioned the approach might be similar to what happens with U2F already.
@PVince81 it does seem to work out, yup 🎉 And allows basic auth. by using application passwords. Pretty cool.
I think a switch to enable/disable this config in the Admin > User Authentication pane when OAuth2 / U2F apps are enabled would be desirable (additionally to the obscure occ config:system:set token_auth_enforced --type boolean --value true)
Closing here, will request that feature in a different ticket.
Following a discussion on the OAuth2 app, we should make the regular user password not to be allowed as a way to authenticate with ownCloud when enforced. Using, for non-compatible clients (e.g. DAV, WND...), an application password instead.
@DeepDiver1975 mentioned the approach might be similar to what happens with U2F already.
cc/ @PVince81 @butonic @pmaier1 @michaelstingl
The text was updated successfully, but these errors were encountered: