WHMCS Services Forum
2FA Security 2.0.1 — installation and optional migration - Printable Version

+- WHMCS Services Forum (https://forum.whmcsservices.net)
+-- Forum: WS Modules (https://forum.whmcsservices.net/forumdisplay.php?fid=8)
+--- Forum: Addons Modules (https://forum.whmcsservices.net/forumdisplay.php?fid=9)
+---- Forum: 2FA Security (https://forum.whmcsservices.net/forumdisplay.php?fid=40)
+---- Thread: 2FA Security 2.0.1 — installation and optional migration (/showthread.php?tid=649)



2FA Security 2.0.1 — installation and optional migration - whmcsservices - 10-08-2026

Fresh installation
1. Upload the ZIP's modules folder into the WHMCS root.
2. Activate/configure 2FA Security and enable the PIN/Email providers as needed.
3. Leave Migrate Existing 2FA unticked. No legacy import, preservation, or verification runs for a fresh installation.

Replacing the old Pin 2FA addon, Email 2FA addon, or both
1. Back up the database and module files. Upload the combined package. It replaces the physical security/pin and security/email provider files.
2. Activate/configure the combined addon while the old addons are still active. Tick Migrate Existing 2FA and save. Use a valid license for the licensed package.
3. Open the combined addon's Migration tab and click Run Migration / Restore Tables. Only existing old enrollment tables are imported; missing old providers are skipped. This also preserves old tables and shared templates in protected copies.
4. Check Legacy Migration Verification on that page. Review BOTH User Logs and Admin Logs and test existing logins before deactivation. Keep old addons active if any active enrollment is missing or conflicting.
5. After verification, deactivate the old addons normally.
6. Immediately return to Migration and click Run Migration / Restore Tables again. This restores any deleted old tables and shared templates from protected copies. The old addons themselves do not need patching.
7. Verify logins again. Untick Migrate Existing 2FA Security and save once migration is complete; the Migration navigation item disappears.
8. You can now delete the Pin 2FA addon, Email 2FA addon, or both

Verification appears only on the dedicated Migration page while the option is enabled, never on the ordinary User/Admin log pages. Checking the option does not automatically execute migration; use the button.
Avoid login activity between old-addon deactivation and restoration, because their deactivation can temporarily delete shared email templates.
Existing combined enrollments take priority. Legacy PIN hashes are copied unchanged. Legacy pin/email provider selections are retained. Earlier combined pin2fa/email2fa selections are restored to pin/email only when migration is explicitly run.
Physical provider overwrite and live logins require testing; no automatic file rollback is included.
Obsolete security/pin2fa and security/email2fa folders from earlier combined releases can be moved outside modules/security after migration; uploading a ZIP does not remove them.

Protected copies preserve ws_pin2fa, ws_emailtwofa, ws_iptrust2fa_setting, ws_iptrust2fa_ip and the shared 2FA email templates. Do not remove protected copies before migration/restoration is complete.
Syntax and mocked migration/preservation/widget/log tests have passed. Live WHMCS/MySQL and login testing remain required