# Allow authentication methods to be combined

**URL:** https://discuss.tryton.org/t/allow-authentication-methods-to-be-combined/2681
**Category:** Feature
**Created:** [May 5, 2020, 2:45pm UTC](https://discuss.tryton.org/t/allow-authentication-methods-to-be-combined/2681 "2020-05-05T14:45:57Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![dave](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/d/ee7513/32.png) [@dave](https://discuss.tryton.org/u/dave)
#### Post date: [May 5, 2020, 2:45pm UTC](https://discuss.tryton.org/t/allow-authentication-methods-to-be-combined/2681/1 "2020-05-05T14:45:57Z")

</div>

## Rationale

At the moment each authentication method is tried in turn, and the first that succeeds allows login. So to implement and use two-factor, or multi-factor, authentication there needs to be a `_login_xxx` method added to the User model for the specific combination of authentication methods that an administrator wants to allow. This means that modules that implement one specific authentication method also need to know about all the other authentication methods that are available to be able to support multi-factor authentication with them, or additional modules need to be created just to add that combination of authentication methods.

## Proposal

Also allow the authentication methods to be combined together in such a way that each individual method must succeed in turn to allow login. This could be done by allowing a plus (`+`) character to be used in the `session`.`authentications` configuration option. These combined authentication methods would then be tried in turn, each must succeed and return the same user\_id to allow the user to login. If any failed, or didn’t return the same user\_id as the previous method, then the next authentication method following a comma (`,`) would be tried.

Example:

```
[session]
authentications = password+sms,method2+method3,method4

```

So this would require authentication by `password` followed by `sms`, or by `method2` followed by `method3`, or by `method4` alone. Where methods 2-4 could be things like [Kerberos](https://en.wikipedia.org/wiki/Kerberos_(protocol)), [Time-based One-Time Passwords (TOTP)](https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm), or [Universal 2nd Factor (U2F)](https://en.wikipedia.org/wiki/Universal_2nd_Factor). And each of these additional authentication methods could then be implemented without needing to know about each other.

## Implementation

> **[Allow authentication methods to be combined (#9303) · Issues · Tryton / Tryton...](https://foss.heptapod.net/tryton/tryton/-/issues/9303)**
>
> Following on from: https://discuss.tryton.org/t/allow-authentication-methods-to-be-combined/2681

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [May 5, 2020, 2:54pm UTC](https://discuss.tryton.org/t/allow-authentication-methods-to-be-combined/2681/2 "2020-05-05T14:54:04Z")

</div>

> [@dave](#):
>
> each must succeed to allow the user to login

I think they should also all return the same user ID otherwise it must fail.

---

<div class="post-metadata">

### Author: ![dave](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/d/ee7513/32.png) [@dave](https://discuss.tryton.org/u/dave)
#### Post date: [May 5, 2020, 3:00pm UTC](https://discuss.tryton.org/t/allow-authentication-methods-to-be-combined/2681/3 "2020-05-05T15:00:51Z")

</div>

Yes, indeed, I should probably have mentioned that in the implementation details.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [June 4, 2020, 4:00pm UTC](https://discuss.tryton.org/t/allow-authentication-methods-to-be-combined/2681/4 "2020-06-04T16:00:00Z")

</div>

This topic was automatically closed after 14 days. New replies are no longer allowed.
