Two-Factor Authentication (2FA) for developer portal
Currently login to the developer portal https://developers.exlibrisgroup.com/ requires username and password. If a user account associated with an organisation is compromised this gives the malicious actor access to use/create API keys to do anything they want in Alma.
For example a malicious actor could create an API key which allows them to access all the user information stored in Alma.
Access to manage API keys should be locked down with 2FA, password login is not sufficient.
5
votes
Peter Brotherton
shared this idea
-
Steven commented
Good idea. Please support this.
-
Lynne Billington commented
Great idea!