Metadata-Version: 2.4
Name: ocyan.plugin.wagtail_2fa
Version: 0.1.1
Summary: Ocyan integration for Wagtail administrator two-factor authentication.
Author: MandelBlogStack
License-Expression: LicenseRef-Proprietary
Classifier: Framework :: Django
Classifier: Framework :: Wagtail
Classifier: Environment :: Plugins
Classifier: Programming Language :: Python :: 3.12
Requires-Python: <3.13,>=3.12
Description-Content-Type: text/markdown
Requires-Dist: Django<5.3,>=5.2
Requires-Dist: Wagtail<8,>=7
Requires-Dist: wagtail-2fa<2,>=1.8
Requires-Dist: ocyan.core<2,>=1.2.14
Requires-Dist: ocyan.main<3,>=2.0.2

# `ocyan.plugin.wagtail_2fa`

This package integrates upstream `wagtail-2fa` and `django-otp` into Ocyan
Wagtail hosts. It registers the upstream applications and verification
middleware and makes existing superuser sessions browser-session-only after a
response. It does not implement OTP itself, select MFA providers, manage users,
alter permissions, or enable MFA for a project automatically.

## Configuration

Set `WAGTAIL_2FA_REQUIRED = True` in the production settings of a project after
its administrator MFA rollout is approved. Upstream `wagtail-2fa` then requires
verified OTP for users who can access the Wagtail administration. Keep Django's
session cookie security settings (`SESSION_COOKIE_SECURE`, `SESSION_COOKIE_HTTPONLY`
and `SESSION_COOKIE_SAMESITE`) owned by the host; this plugin preserves them.

The integration is validated with Python 3.12, Django 5.2 and Wagtail 7. No
credentials, OTP seeds, recovery codes or external authentication services are
handled by this package.
