Make email OTP login off by default

This commit is contained in:
Thanakorn
2026-09-14 15:38:36 +07:00
parent 21148bf50c
commit 6b3a590aa9
9 changed files with 33 additions and 32 deletions
+5 -6
View File
@@ -39,13 +39,12 @@ if (!defined('NODE_EMIT_SECRET')) {
}
// ── Login OTP ────────────────────────────────────────────────────────────────
// Email OTP on sign-in. LEAVE THIS TRUE unless password-only sign-in is wanted
// on purpose (e.g. a demo). It fails safe: anything other than the boolean
// false — the constant being absent included — keeps the OTP step on. While it
// is off, every sign-in is logged as OTP_BYPASSED and the login page and top
// bar both say so. Password-reset OTPs are not affected.
// Email OTP on sign-in. OFF BY DEFAULT: only the boolean true turns it on —
// anything else, the constant being absent included, leaves sign-in password
// only (logged as OTP_BYPASSED, shown on the login page and top bar). Turn it
// on only with working SMTP. Password-reset OTPs are not affected.
if (!defined('OTP_REQUIRED')) {
define('OTP_REQUIRED', true);
define('OTP_REQUIRED', false);
}
// ── Usage packages ───────────────────────────────────────────────────────────