Authentication & User Access Control
Standalone Qwiki features a lightweight, file-based Role-Based Access Control (RBAC) engine stored in users.json. It requires no external database while providing enterprise-grade security using PHP Bcrypt password hashing (password_hash()), stateless HMAC-SHA256 password resets, and native RFC 6238 Two-Factor Authentication (2FA).
[!NOTE] This advanced topic page is primarily provided as an illustration of Qwiki's feature set and documentation style. Feel free to delete it once you're familiar with the system.
👥 User Roles & Permissions
| Action / Capability | Viewer | Admin |
|---|---|---|
| Read Documentation (Markdown, HTML, PDF, Google Docs) | ✅ | ✅ |
| Search & Filter Navigation | ✅ | ✅ |
Manage Personal Email & 2FA (👤 Account & Security) |
✅ | ✅ |
| Resize Sidebar Width | ✅ | ✅ |
| Create / Upload / Edit Documents & Categories | ❌ | ✅ |
| Edit HTML Documents with SunEditor WYSIWYG | ❌ | ✅ |
Generate Vector Charts & Diagrams (uploads/) |
❌ | ✅ |
| Drag & Drop Menu Reordering | ❌ | ✅ |
| Upload Images inside Markdown Editor | ❌ | ✅ |
Manage Users, Roles & Passwords (👥 Users) |
❌ | ✅ |
Configure Wiki 2FA Policy & SMTP (⚙️ Site Settings) |
❌ | ✅ |
🔑 Default Credentials
- Username:
admin - Password:
admin
[!IMPORTANT] Change the default admin password or add a new admin account in
👥 Usersimmediately after deploying to production.
🔄 Self-Service Password Reset
Users can securely reset their own passwords if an email address is associated with their account:
- Email Verification: Users configure their verified email under
👤 Account & Security. - Stateless HMAC Tokens: Reset links contain cryptographically signed tokens (
action=reset_password&token=...) expiring in 2 hours. Tokens incorporate a cryptographic slice of the user's current password hash, guaranteeing 0 disk writes during request generation and immediate, automatic invalidation once the password is changed. - Air-Gapped & Offline Fallback: In environments without outbound email or SMTP, administrators can click
🔗 Reset Linknext to any user in the👥 Usersmanagement modal to copy a 24-hour offline reset link directly to their clipboard.
🛡️ Two-Factor Authentication (2FA / TOTP)
Standalone Qwiki implements pure native RFC 6238 Time-Based One-Time Passwords (TOTP) without requiring any external libraries or cloud dependencies.
Features
- Broad Authenticator Compatibility: Compatible with Google Authenticator, Bitwarden, 1Password, Microsoft Authenticator, and Aegis.
- Offline Client-Side QR Codes: Secret QR codes are rendered as pure SVG vector graphics in the browser with zero external calls to third-party image APIs.
- 8 Emergency Recovery Codes: Users receive eight single-use 10-character recovery codes upon enrollment. Each code is BCrypt-hashed in
users.jsonand consumed on first use. - Configurable Wiki Policies: Administrators can configure the wiki-wide policy in
⚙️ Site Settings:Optional: Users can choose whether to enable 2FA on their account (default).Required for Admins: All administrators must enroll in 2FA before accessing administrative tools.Required for All: All users (viewers and admins) must enroll in 2FA.Disabled: Two-factor authentication is globally disabled.
🚨 Emergency CLI Recovery
If an administrator loses access to both their authenticator app and their recovery codes, 2FA can be safely disabled from the server terminal:
- Connect to the server terminal via SSH.
- Run the recovery command with the target username:
php bin/reset-2fa.php admin - Log in with the standard username and password.
✉️ Outbound Email & SMTP Delivery
Outbound mail (password resets, email verification) supports two delivery modes configured in ⚙️ Site Settings:
- Direct Socket SMTP: Connects directly via
stream_socket_client()with support for TLS (STARTTLS port 587) and SSL (port 465) withAUTH LOGINauthentication. Includes a built-in "Test Connection" button. - Native PHP
mail()Fallback: If custom SMTP is disabled, Standalone Qwiki uses the server's nativemail()function with-fenvelope sender parameter alignment.