Topic-icon Unlink an account

Active Subscriptions:

None
9 years 8 months ago #46424 by uglyeoin
Unlink an account was created by uglyeoin
I want to unlink my account from my profile. I linked the wrong account, and I need to get the right one for social channels.

I've had problems because I use two factor authentication, so I'd like Two Factor Authentication dealt with in your login module.

Also, it would be great if you could tie together users by more than one field. I have multiple email addresses, so does everyone, email, although unique, is not actually a very good indicator of a person. I don't want multiple accounts for one user where possible. Thus it would be nice to tie a person together by name, and ask them to verify if they have logged in previously with a differing account. Perhaps even offering them part of the email address, obsfucating other parts e.g. first 4 letters and final 4. I'm sure there are tonnes of JohnSmith@aol JohnSmith@gmail so just the beginnning is not enough.

It would be nice to have multiple Twitter feeds potentially. That requires multiple email addresses. I still want to be one administrator though.
The topic has been locked.
Support Specialist
9 years 8 months ago #46427 by alzander
Replied by alzander on topic Unlink an account

I want to unlink my account from my profile. I linked the wrong account, and I need to get the right one for social channels.

Right now, you'd need to either:
* Delete the mapping from the JFBConnect - User Map area
* On the front-end, login to Joomla with the 'right' account and use the "Reconnect" button for Twitter. That will update the Twitter association to the currently logged in user.

I've had problems because I use two factor authentication, so I'd like Two Factor Authentication dealt with in your login module.

The SCLogin module does handle TFA. If you're running into issues using TFA with SCLogin, let me know what they are.

Also, it would be great if you could tie together users by more than one field.

This is extremely hard to do without opening up huge security problems. We've thought about and investigated some options, but it's hard. We rely on the social networks to provide verification of the user's email address, which is why we can trust it to authenticate a user and update their mapping. Since accounts can be created on any social network with any "Name", if someone knows your name, they could create a fake account and try to login to your site with it and associate it to your existing Joomla account. There would have to be a lot of other verification steps here.. and many users may not have (or at least know they have) a Joomla password, so we can't just ask them to verify that.

It would be nice to have multiple Twitter feeds potentially. That requires multiple email addresses. I still want to be one administrator though.

Currently, we have a 1-1 mapping of user's to a social network. We've honestly never thought of having multiple social networks be associated to the same user. To have multiple feeds right now, you'd need to create another user on your site. That user can be a front-end "Registered" user only and you can even block the account after you get the feed setup, but it will have to be there for JFBConnect to setup the right permissions to fetch the feed.

I hope that all helps explain and makes sense. If you have any questions or feedback, we'd love to hear it.

Thanks,
Alex
The topic has been locked.
Active Subscriptions:

None
9 years 8 months ago #46434 by uglyeoin
Replied by uglyeoin on topic Unlink an account
Got it, good answers as ever, cheers. Definitely agree with the security issue, a valid point.

Re: the TFA issue, I'm logged in with super admin on the front end, but TFA doesn't appear. So I can log in with my social accounts, but I cannot log in otherwise. I tried logging in, and then reconnecting my Twitter account, but it had an error about two factor authentication. I'll try to replicate the full steps and post
The topic has been locked.
Support Specialist
9 years 8 months ago #46442 by alzander
Replied by alzander on topic Unlink an account
Ahh.. the Two Factor Authentication features work when using the standard Joomla authentication. We don't support TFA while logging in with a social network, if that's what you're looking for.

That's a feature we hadn't thought about before. Again, we rely on the social networks themselves to do a bit of validation on the user (many won't let you login from unknown IPs or even have their own TFA scheme). I'm not sure this is something we'd implement in JFBConnect as it's one more 'token' a user might need on top of anything else the social networks might already require or be setup for. If that's what you're looking for though, let me know.

Thanks,
Alex
The topic has been locked.
Active Subscriptions:

None
9 years 8 months ago - 9 years 8 months ago #46450 by uglyeoin
Replied by uglyeoin on topic Unlink an account
These screenshots replicate the issue. I login using Twitter. Then it asks me to register again Twitter doesn't give you the email address so we need to do this, or if I have already got an account I can login that way. Then when I try to, it gives me the TFA issues. I'm not sure the following images will display, I certainly can't view them as I do not have the correct permissions.


File Attachment:


File Attachment:
Last edit: 9 years 8 months ago by uglyeoin.
The topic has been locked.