Security is very important to TownNews and BLOX CMS, so we provide a number of options to help users protect their account access from bad actors, including a client trust token mechanism and an optional two-factor authentication method.
By default, BLOX utilizes a client trust token on a particular device which must be validated on admin accounts via the user’s email address every three months. This means that if BLOX doesn’t recognize a device, it will ask for the user to validate by sending a one-time validation code to the email address that associated with their user account. This process ensures that the user logging into the admin account also has access to the user's email account.
