DEV Community

Cover image for OpenSparrow v4.1 adds optional two-factor login by email
Tomasz
Tomasz

Posted on

OpenSparrow v4.1 adds optional two-factor login by email

OpenSparrow v4.1 adds optional two-factor login by email, streaming answers in Ask AI, and PostgreSQL views to the External API — plus a security hardening pass across the write paths.

Two-factor login, off by default

System → Settings → Login Security gains a toggle: after a correct password, accounts with a contact email must enter a 6-digit code sent to their inbox — the pattern banking apps use, now built into your self-hosted instance.

  • Opt-in, per account — off by default; accounts without an email keep password-only login, so nobody gets locked out during rollout
  • Abuse-resistant — codes expire after 60 seconds, allow 5 attempts, sending is throttled per IP and username, and a delivery failure fails closed instead of skipping the factor
  • No new infrastructure — reuses your existing cron/SMTP email settings and the contact fields from v3.3; no migration

Ask AI streams its answers

Responses arrive token by token instead of one block at the end — long analyses start appearing immediately while the model is still writing.

  • Clickable record links — answers reference rows as links straight to the record
  • The answer of record — the streamed text is a preview; the final payload carries the cleaned-up version with markdown, links and follow-up suggestions
  • A working off switch — the admin's Ask AI enable flag finally gates the API (403) and hides the menu button and FAB

External API now serves PostgreSQL views

System → API can bind a registered PostgreSQL view — aggregates included — instead of only a raw table, which is how integrations usually want to consume data:

  • Columns and filters are re-checked against the live database on every save and request; an altered view answers a clean 404, never a 500
  • Views sort by their first selected column (no guaranteed id); tables keep id DESC
  • Fixed: freshly generated API keys are adopted on save instead of being regenerated on every re-save

Also in this release

  • CSV import moved to a proper service layer; cron output is plain text
  • Version info moved from the login page to the footer
  • New records open on the first tab

Following this series?

OpenSparrow v4.0 adds a JSONB column type, public read-only table sharing, and many-to-many editing directly on the grid

Websites

https://opensparrow.org

Top comments (2)

Collapse
 
wrobeltomasz profile image
Tomasz •

I encourage you to join the discussion; I'll do my best to answer any questions you may have about the system.

Collapse
 
suppdevbot profile image
Info Comment hidden by post author - thread only accessible via permalink
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to

Some comments have been hidden by the post's author - find out more