Page MenuHomePhabricator

T4NeGMp7P4en
User

Projects

User does not belong to any projects.

Today

  • No visible events.

Tomorrow

  • No visible events.

Sunday

  • No visible events.

User Details

User Since
May 4 2025, 9:53 AM (43 w, 4 d)
Availability
Available
LDAP User
Unknown
MediaWiki User
T4NeGMp7P4en [ Global Accounts ]

Recent Activity

Feb 2 2026

T4NeGMp7P4en created T416159: Allow passkey to be named.
Feb 2 2026, 11:57 AM · FY2025-26 WE 4.6 - Account Security (WE 4.6.9 (Passwordless login and passkey promotion)), MediaWiki-extensions-OATHAuth

Jan 28 2026

T4NeGMp7P4en added a comment to T415808: Cannot Use Modern Passkeys without Legacy Security Keys or TOTP App.

This is currently working as intended. Passkeys are only usable as part of 2FA, not passwordless login, and require another 2FA to be enabled. T321708: MediaWiki should support passwordless login with passkeys is the related feature request.

Jan 28 2026, 5:43 PM · MediaWiki-extensions-OATHAuth
T4NeGMp7P4en updated the task description for T415808: Cannot Use Modern Passkeys without Legacy Security Keys or TOTP App.
Jan 28 2026, 5:33 PM · MediaWiki-extensions-OATHAuth
T4NeGMp7P4en created T415808: Cannot Use Modern Passkeys without Legacy Security Keys or TOTP App.
Jan 28 2026, 5:30 PM · MediaWiki-extensions-OATHAuth

Dec 26 2025

T4NeGMp7P4en added a comment to T410946: 2FA removal UI displays incorrect message about recovery codes.
Dec 26 2025, 6:51 PM · MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Dec 14 2025

T4NeGMp7P4en added a comment to T410946: 2FA removal UI displays incorrect message about recovery codes.

In my test on jawiki, I found that deleting security key can also show this incorrect warning. FYR.

Dec 14 2025, 9:15 AM · MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Dec 2 2025

T4NeGMp7P4en added a comment to T399657: Update existing 2FA documentation.

https://meta.wikimedia.org/wiki/User:TBurmeister_(WMF)/Sandbox/2FA is now a final draft, with just a couple small TODOs left (I've opened threads about with the team to resolve). Feedback on this draft is welcome as comments on this task, or on the Talk page.

Dec 2 2025, 11:08 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), Tech-Docs-Team, MediaWiki-extensions-OATHAuth, Documentation

Nov 29 2025

T4NeGMp7P4en added a comment to T399657: Update existing 2FA documentation.

If it helps, please refer ja:H:2FA. It is already updated for new 2FA system.
It could be a basis to rewrite other documents.

Nov 29 2025, 3:45 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), Tech-Docs-Team, MediaWiki-extensions-OATHAuth, Documentation

Oct 25 2025

T4NeGMp7P4en added a comment to T408294: Regeneration of Recovery Codes doesn't work properly.

Thanks for the report!

I've found numerous other bugs... So many tasks filed off the back of this :(

Oct 25 2025, 6:38 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a comment to T408294: Regeneration of Recovery Codes doesn't work properly.

Ok, I specifically understand now.

Keep regenerating codes, it doesn't actually regenerate, you lose one at a time until they're all gone...

Oct 25 2025, 5:32 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a comment to T408297: Recovery codes aren't consumed when encryption is enabled.

For your information, at jawiki, it successfully consumes and doesn't show the used code when I login with recovery code.

Oct 25 2025, 3:37 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MW-1.45-release, MediaWiki-extensions-OATHAuth
T4NeGMp7P4en updated the task description for T408294: Regeneration of Recovery Codes doesn't work properly.
Oct 25 2025, 3:18 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en created T408294: Regeneration of Recovery Codes doesn't work properly.
Oct 25 2025, 2:47 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Oct 23 2025

T4NeGMp7P4en added a comment to T354030: Allow viewing recovery codes again?.

In my opinion, if we can regenerate recovery codes only with one click, we don't need the option to view existing recovery codes. I think the risk of storing recovery codes in a recoverable format (I mean not using hash function) is much more bigger than the benefit.

Oct 23 2025, 4:45 PM · MediaWiki-extensions-OATHAuth

Oct 22 2025

T4NeGMp7P4en added a comment to T407167: Only One Recovery codes given.

Patch is not merged, so task is not resolved.

Oct 22 2025, 4:32 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en closed T407167: Only One Recovery codes given, a subtask of T352856: Recovery code improvements, as Resolved.
Oct 22 2025, 1:59 PM · Epic, MediaWiki-extensions-OATHAuth
T4NeGMp7P4en closed T407167: Only One Recovery codes given, a subtask of T406281: Display new recovery code after user logs in with recovery code, as Resolved.
Oct 22 2025, 1:59 PM · MediaWiki-extensions-OATHAuth, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support)
T4NeGMp7P4en closed T407167: Only One Recovery codes given, a subtask of T406501: OATHAuth Recovery Code code improvement suggestions, as Resolved.
Oct 22 2025, 1:59 PM · MW-1.45-notes (1.45.0-wmf.22; 2025-10-07), FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en closed T407167: Only One Recovery codes given as Resolved.
Oct 22 2025, 1:59 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a comment to T407167: Only One Recovery codes given.

I checked that the patch works well. Thank you so much!

Oct 22 2025, 1:59 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a comment to T407167: Only One Recovery codes given.

image.png (252×664 px, 14 KB)

This is a significant problem. As loss of authenticator requires at a minimum TWO codes, that may only be used once to reset an account. (One to log on, one to disable).

That is no longer true. It used to be that you had to reauthenticate when disabling 2FA, but that has changed. Now, you can take any 2FA management action (adding or removing 2FA methods) within one hour of logging in. If you visit Special:AccountSecurity more than one hour after logging in, you will need to reauthenticate.

Of course the user could get logged out, or fail to fix their 2FA setup within an hour, or ignore the messages we're adding T406281, and those may be reasons to increase the number of recovery codes. But it is now possible to redo your 2FA setup with only one recovery code, you no longer need a minimum of two.

Oct 22 2025, 3:51 AM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Oct 17 2025

T4NeGMp7P4en added a comment to T407167: Only One Recovery codes given.

@T4NeGMp7P4en Why are you adding this as a subtask to every barely related task you can find?

Oct 17 2025, 2:57 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a subtask for T406501: OATHAuth Recovery Code code improvement suggestions: T407167: Only One Recovery codes given.
Oct 17 2025, 2:53 PM · MW-1.45-notes (1.45.0-wmf.22; 2025-10-07), FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a parent task for T407167: Only One Recovery codes given: T406501: OATHAuth Recovery Code code improvement suggestions.
Oct 17 2025, 2:53 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Oct 15 2025

T4NeGMp7P4en added a subtask for T352856: Recovery code improvements: T407167: Only One Recovery codes given.
Oct 15 2025, 6:30 PM · Epic, MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a subtask for T405873: Recovery options doesn't show existing Recovery Codes: T407167: Only One Recovery codes given.
Oct 15 2025, 6:30 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a subtask for T406382: Make "recovery-codes.txt" file name translatable: T407167: Only One Recovery codes given.
Oct 15 2025, 6:29 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), I18n, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en added a subtask for T406281: Display new recovery code after user logs in with recovery code: T407167: Only One Recovery codes given.
Oct 15 2025, 6:29 PM · MediaWiki-extensions-OATHAuth, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support)
T4NeGMp7P4en added parent tasks for T407167: Only One Recovery codes given: T352856: Recovery code improvements, T405873: Recovery options doesn't show existing Recovery Codes, T406281: Display new recovery code after user logs in with recovery code, T406382: Make "recovery-codes.txt" file name translatable.
Oct 15 2025, 6:29 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Oct 14 2025

T4NeGMp7P4en added a comment to T407167: Only One Recovery codes given.

Hello - thanks for filing this. I'm not sure what is meant by "Instead, automatically disable 2fa when recovery code is used." Recovery codes (and the former scratch tokens, which are still usable via older TOTP/authenticator apps) should never disable 2fa for a user. They should instead facilitate access to an account with 2fa enabled if an authenticator app, FIDO key or other 2fa factor is lost, damaged, stolen, etc. The current single recovery code does regenerate each time it is used and a new code can be copied or downloaded under the new Recovery options section on Special:AccountSecurity. We are currently working to improve this user experience in T406281 and hope to have that completed this quarter (October through December 2025).

Oct 14 2025, 3:17 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en updated the task description for T407167: Only One Recovery codes given.
Oct 14 2025, 2:56 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Oct 13 2025

T4NeGMp7P4en updated the task description for T407167: Only One Recovery codes given.
Oct 13 2025, 10:48 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
T4NeGMp7P4en created T407167: Only One Recovery codes given.
Oct 13 2025, 10:47 PM · MW-1.45-notes (1.45.0-wmf.25; 2025-10-28), MW-1.45-release, FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth