Skip to content

Proposal to Integrate Two-Factor Authentication (2FA) Support in CSPro and CSEntry Sync Workflows #18

Description

@lestcape

Following the security enhancements proposed for CSWeb (Issue #2), it is critical to extend Two-Factor Authentication (2FA) support to CSPro and CSEntry. Since CSEntry and CSPro clients frequently connect to CSWeb to deploy applications and synchronize data, usernames and passwords alone represent a significant vulnerability if a device is compromised or intercepted.

When a user logs into a CSWeb server from CSPro or CSEntry to deploy or download data, the environment must prompt for the 2FA verification token immediately after validating the primary credentials. Also, before saving synchronization credentials or initiating a data transfer connection (SyncId / SyncPassword), both applications must support the secondary authentication challenge. To maintain operational efficiency in field data collection without adding infrastructure costs, we propose leveraging the same free, robust mechanisms implemented in CSWeb.

By requiring 2FA before storing or utilizing sync credentials, we ensure that even if a supervisor's or enumerator's password is leaked, unauthorized devices cannot spoof the server, download sensitive survey structures, or upload fraudulent data.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions