I am currently trying to implement 2FA in my Django Application. The first thing I've done is to modify the Meta class in the UserSerializer class to add two fields enabled (indicates if 2FA is enabled for a user) and secret_key (the key to generate OTP, that is shared to the user when he enables 2FA).
To minimally modify the login flow, I've modified the form that is sent to generate the access tokens to include a new field "otp". The user can fill it or not, and the backend will check if the user has 2FA enabled, and if yes, if the OTP is correct.
Without 2FA, the login is simply a POST request with body {"username": usr, "password": pwd}. This has become a POST request with body {"username": usr, "password": pwd, "otp": otp}. If a user user hasn't enabled 2FA, he can simply leave the opt field blank.
My urls.py looks like this:
path("api/token/", TokenObtainPairView.as_view(), name="token_obtain_pair")
My idea is to override TokenObtainPairView to adapt to the new request. From what I've found, I have to change the validate method, but I don't really have a clue as to how to do that. I probably would have to get the values of the enabled and secret_key fields of the user (based on username) to generate the OTP (if relevant) and check it against the otp field. Problem is, I don't know how to do that and I'm getting a little bit lost in the simple-jwt implementation.