feat(scripts): Forgejo 2FA / account access-review evidence tool (#79) #99
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!99
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/79-2fa-access-review"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes #79.
scripts/access-review-2fa.py— stdlib-only tool listing every Forgejo account + security flags (2FA, admin, active, restricted, prohibit-login, last login) via the v16 admin users API, rendering a dated Markdown report for the ISO 27001 access-control review (bitborg-docs#30). 2FA derived from theis_2fa_enabledlist filter (PR 12091, not a body field). Reuses aread:adminPAT (the gitborg-token-audit account, #75). Runbook § Access review documents running it + committing the report to a private ISMS evidence store. Admins without 2FA are flagged (expected only for PAT-only service accounts).Verified: endpoint + filter confirmed against prod swagger 16.0.0; render verified with mock data; py_compile clean; markdownlint clean.
Pairs with the private ISMS evidence update (evidence store + SoA 5.18).
219e4e539045e0d62d6f45e0d62d6f3539ebf5e53539ebf5e5b860766d49