diff --git a/apps/common/permissions.py b/apps/common/permissions.py index c2d2cf4fa..869107a58 100644 --- a/apps/common/permissions.py +++ b/apps/common/permissions.py @@ -57,6 +57,9 @@ class UserConfirmation(permissions.BasePermission): confirm_type = ConfirmType.ReLogin def has_permission(self, request, view): + if not settings.SECURITY_VIEW_AUTH_NEED_MFA: + return True + confirm_level = request.session.get('CONFIRM_LEVEL') confirm_time = request.session.get('CONFIRM_TIME')