Page MenuHomePhabricator
Feed Search

Wed, Jan 28

Tonymetz removed a watcher for IPv6: Tonymetz.
Wed, Jan 28, 10:48 PM
Tonymetz removed a watcher for Elasticsearch: Tonymetz.
Wed, Jan 28, 10:48 PM
Tonymetz removed a watcher for doc.wikimedia.org: Tonymetz.
Wed, Jan 28, 10:48 PM
Tonymetz removed a watcher for Mail: Tonymetz.
Wed, Jan 28, 10:47 PM
Tonymetz removed a watcher for MediaWiki-extensions-Arrays: Tonymetz.
Wed, Jan 28, 10:47 PM
Tonymetz removed a watcher for MediaWiki-Email: Tonymetz.
Wed, Jan 28, 10:47 PM
Tonymetz removed a watcher for MediaWiki-Debian: Tonymetz.
Wed, Jan 28, 10:20 PM
Tonymetz removed a watcher for Gender-Support: Tonymetz.
Wed, Jan 28, 10:20 PM
Tonymetz removed a watcher for events: Tonymetz.
Wed, Jan 28, 10:20 PM
Tonymetz removed a watcher for Developer Productivity: Tonymetz.
Wed, Jan 28, 10:20 PM
Tonymetz removed a watcher for Data-Services: Tonymetz.
Wed, Jan 28, 10:20 PM
Tonymetz removed a watcher for good first task: Tonymetz.
Wed, Jan 28, 10:20 PM
Restricted Application added a project to T227237: Create PasswordCannotMatchEmail password policy: MediaWiki-Platform-Team.
Wed, Jan 28, 12:32 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MediaWiki-Core-AuthManager

Tue, Jan 27

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.
Microsoft Edge	145.0.3800.22 (Official build) beta (64-bit) 
Revision	7be60baa68d705e70f501a1837f69b4ddf671159
Chromium version	145.0.7632.18
Operating system	Windows 11 Version 25H2 (Build 26220.7653)
Tue, Jan 27, 7:47 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Dec 10 2025

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

hi guys i'll see if I can repo. thanks for the continued effort . i've since removed tokens but i'll try to help confirm the resolution.

Dec 10 2025, 2:56 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Oct 13 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

@Tonymetz Also, I am having trouble understanding what is the actual workflow that doesn't work for you. Maybe I'm just confused, but you seem to be talking about several different ways to log in.
Can you test things again and write down step-by-step

I'm happy to help test and support this. thanks for giving it some attention. it's been a few months so i'll try to reproduce a better test case.

Oct 13 2024, 10:17 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Oct 11 2024

Tonymetz added a comment to T376021: Migrate WebAuthn on Wikimedia wikis to central domain.

applying the patch in T358771 could fix a large part of this issue and enable webauthn to work across domains.

Oct 11 2024, 3:00 AM · MediaWiki-Platform-Team, SUL3, MediaWiki-extensions-OATHAuth

Oct 3 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

thanks for helping provide the context that is helpful. I'm happy to help provide some support on this if there's interest. I've worked on 2FA efforts before, and users require a bit of education and notification to help move adoption forward.

Oct 3 2024, 10:16 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

I imagine the number of people affected is probably pretty low, but not zero. Otherwise we'd probably hear about it from more users.

See also: T376021: Migrate WebAuthn on Wikimedia wikis to central domain

Oct 3 2024, 10:03 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

i did another round of testing and the feature still appears to be broken. The issue is likely locking users out of their accounts. There doesn't seem to be telemetry on the issue, so I worry that wikimedia staff is not paying attention to the number of users who are getting locked out.

Oct 3 2024, 4:35 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Jun 21 2024

Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

Let me know if my assessment is correct

Jun 21 2024, 11:38 PM · MediaWiki-Platform-Team, MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth

May 24 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

the people who want to use webauthn do. What's the point of the feature if it's broken?

May 24 2024, 9:27 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

a monthly reminder that ...

May 24 2024, 4:36 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

since most people don't use 2FA in the first place.

May 24 2024, 4:25 PM · MediaWiki-Platform-Team, MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

Are those related to this task?

May 24 2024, 4:20 PM · MediaWiki-Platform-Team, MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth

May 10 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

what would be helpful would be an estimate.

May 10 2024, 10:21 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

May 7 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

@taavi are we targeting 2024 or 2025 on this one?

May 7 2024, 12:45 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

Here's a summary of test case failures I've recorded in T358771

May 7 2024, 12:41 AM · MediaWiki-Platform-Team, MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

any word on this one? in my personal experience, webauthn is pretty much unusable. I can't return to an existing wiki on another device reliably, and I can't log on a new wiki at all.

May 7 2024, 12:39 AM · MediaWiki-Platform-Team, MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth

Apr 29 2024

Tonymetz added a comment to T227237: Create PasswordCannotMatchEmail password policy.

thanks for the guidance I may take this one. I'll improve the docs if it's better suited for the tag. I appreciate the guidance.

Apr 29 2024, 10:31 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MediaWiki-Core-AuthManager
Tonymetz added a project to T227237: Create PasswordCannotMatchEmail password policy: good first task.
Apr 29 2024, 9:50 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MediaWiki-Core-AuthManager
Tonymetz added a watcher for good first task: Tonymetz.
Apr 29 2024, 6:04 PM
Tonymetz added a comment to T227237: Create PasswordCannotMatchEmail password policy.

@Reedy is this still relevant? It seems similar to includes/password/PasswordPolicyChecks.php L95 checkPasswordCannotBeSubstringInUsername()

Apr 29 2024, 5:30 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MediaWiki-Core-AuthManager
Tonymetz added a watcher for MediaWiki-extensions-Arrays: Tonymetz.
Apr 29 2024, 5:02 AM
Tonymetz added a watcher for MediaWiki-Email: Tonymetz.
Apr 29 2024, 5:01 AM
Tonymetz added a watcher for MediaWiki-Debian: Tonymetz.
Apr 29 2024, 5:01 AM
Tonymetz added a watcher for Mail: Tonymetz.
Apr 29 2024, 5:00 AM
Tonymetz added a watcher for Gender-Support: Tonymetz.
Apr 29 2024, 4:59 AM
Tonymetz added a watcher for events: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for Elasticsearch: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for doc.wikimedia.org: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for Developer Productivity: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for Data-Services: Tonymetz.
Apr 29 2024, 4:57 AM
Tonymetz added a watcher for covid-19: Tonymetz.
Apr 29 2024, 4:54 AM
Tonymetz added a watcher for IPv6: Tonymetz.
Apr 29 2024, 4:50 AM

Apr 28 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Webauthn security tokens are not being passed to wikifunctions.org

Apr 28 2024, 5:34 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Apr 25 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

@taavi any updates on the webauthn tasks merge progress? Are we looking at another 6 weeks?

Apr 25 2024, 4:54 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Apr 19 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.
  1. it is a one-line change
  2. it is a back-port of code from the webauthn repo
  3. reedy & I recorded our testing procedure above with video and code samples
Apr 19 2024, 8:31 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

@Aklapper I don't appreciate the dismissive tone being used. I invested a lot of effort working together with Reedy to reproduce, debug & help formulate a fix. At the very least you could help clarify exactly what the next steps are here.

Apr 19 2024, 8:14 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

It seems the commit was made Mar 5 so it's been 6 weeks. Can you guess how many more weeks it is going to be?

Apr 19 2024, 4:53 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Reedy and I already got this fixed and he submitted a patch. So we're just waiting for it to get merged. What is blocking that?

Apr 19 2024, 4:49 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Can I ask what the blocker is?

Apr 19 2024, 4:31 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

any ETA on this one?

Apr 19 2024, 4:07 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Apr 9 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

There may be another variant of the issue when logging in on meta.wikipedia.org. It seems that the viable webauthn credential list is being filtered either by site or by login device before being presented to the browser. I get a different experience on different browsers.

Apr 9 2024, 6:58 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 26 2024

Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

during testing for T358771 we discovered that login also fails when logging in on the same wiki using a new device.

Mar 26 2024, 5:43 PM · MediaWiki-Platform-Team, MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

what's a good way to track the launch status for this fix? i'm sorry I don't know too much about the deployment process

Mar 26 2024, 5:35 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 7 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

can I help testing out the change on the test env?

Mar 7 2024, 5:40 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 6 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

happy to help -- great partnership on this

Mar 6 2024, 2:11 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

yep cable works like hybrid

Mar 6 2024, 2:02 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

debug session showing how to fix

Mar 6 2024, 1:10 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

screenshot evidence. video inbound
{F42406516}

Mar 6 2024, 1:02 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

wow it worked!

Mar 6 2024, 1:02 AM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 5 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

https://github.com/wikimedia/mediawiki-extensions-WebAuthn/blob/979220702ab45fb4755ed45bd38cbbb05a411c22/resources/login.js#L3 in the repo

Mar 5 2024, 10:33 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

I can break into the login phase (using chrome devtools) at https://en.wikipedia.org/w/extensions/WebAuthn/resources/login.js L3 and reproduce the issue.

Mar 5 2024, 10:32 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

"windows-pc" -- this one is internal (windows hello / TPM)
"iphone" -- this one is iPhone Passkey (added via QR-code) . I think it's supposed to be "hybrid"

Mar 5 2024, 10:25 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Here's my list of tokens on wikimedia

Mar 5 2024, 10:22 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

I believe "HYBRID" is the one that supports the iPhone /passkey based login : https://web.dev/articles/passkey-registration

Mar 5 2024, 10:16 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

(i'm a bit new to webauthn) it seems that the site (wikipedia) sends a list of token public keys / token IDs to the browser to initiate token-based authentication.

Mar 5 2024, 10:04 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

That USB popup looks very Windows/Edge specific. I don't think the message is in our code, or anything we bring in via vendor.

Mar 5 2024, 9:58 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz updated the task description for T358771: Unable to login on iPhone with Passkey Enabled.
Mar 5 2024, 5:00 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

this bug is pretty serious. I'd like to disable 2-FA but i also want to help get it fixed. I'll be locked out of my account if something happens to my first login session

Mar 5 2024, 4:58 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

I'm blocked by another variant of this issue: login from a separate windows machine. I'm being prompted to "insert usb security key" but i have two passkeys registered : (1) from iphone and (1) from another windows machine. I would expect the option to pop a QR-CODE to proceed using iphone passkey

Mar 5 2024, 4:57 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 1 2024

Tonymetz created T358824: Help Users Avoid Creating Duplicate Logins.
Mar 1 2024, 12:32 AM · MediaWiki-CreateAccount-page, MediaWiki-User-login-and-signup

Feb 29 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

if we have measurements of "Authentication process was interrupted " we could segment by user -agent or device to measure incidence of this issue.

Feb 29 2024, 8:37 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

video working experience using "show desktop site" on mobile safari

Feb 29 2024, 8:35 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Wonder if this is some variant of T244088: Logging in at another wiki than WebAuth was set up fails, due to the different mobile domain...

Feb 29 2024, 8:22 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Some more context…

  1. I created two keys using Edge. (1) was a local key and (2) was the iPhone key (using QR code)
Feb 29 2024, 5:25 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz created T358771: Unable to login on iPhone with Passkey Enabled.
Feb 29 2024, 2:53 PM · MediaWiki-Platform-Team (Q3 Kanban Board), MW-1.45-notes (1.45.0-wmf.21; 2025-09-30), Mobile, MediaWiki-extensions-OATHAuth, Security