Allow configuring 2FA for publishing #13253
Replies: 2 comments 3 replies
|
Dear maintainers, this is a very important feature to have, please consider it |
you can use cargo credential providers to save the authentication tokens in more secure places (see https://doc.rust-lang.org/cargo/reference/registry-authentication.html)
yes, but we are a very small team, our todo list is long, and this would be a non-trivial potentially-breaking change that needs integration with cargo and other clients and potentially a completely new publishing API. feel free to help out though, the code is open source 😉 |
Uh oh!
There was an error while loading. Please reload this page.
Right now having access to the token in the credentials file means access to publishing crates freely.
But that file is easily compromised when running malicious code on the machine by accident.
It would be really nice to be able to configure and require 2FA (like TOTP) for publishing such that token alone is not enough to publish a crate.
The reason this is important is that it is unlikely for 2FA (on a secure mobile phone) to be compromised at the same exact time as the token in the credentials file.
Note that this is distinct from securing access to the GitHub account and the whole crates.io account more specifically (I saw some discussions about that).
All reactions