Page MenuHomePhabricator

Tonymetz
User

Projects

User does not belong to any projects.

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Tuesday

  • Clear sailing ahead.

User Details

User Since
Feb 29 2024, 2:44 PM (16 w, 3 d)
Availability
Available
LDAP User
Unknown
MediaWiki User
Tonymetz [ Global Accounts ]

Recent Activity

Fri, Jun 21

Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

Let me know if my assessment is correct

Fri, Jun 21, 11:38 PM · MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth

Fri, May 24

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

the people who want to use webauthn do. What's the point of the feature if it's broken?

Fri, May 24, 9:27 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

May 24 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

a monthly reminder that ...

May 24 2024, 4:36 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

since most people don't use 2FA in the first place.

May 24 2024, 4:25 PM · MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

Are those related to this task?

May 24 2024, 4:20 PM · MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth

May 10 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

what would be helpful would be an estimate.

May 10 2024, 10:21 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

May 7 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

@taavi are we targeting 2024 or 2025 on this one?

May 7 2024, 12:45 AM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

Here's a summary of test case failures I've recorded in T358771

May 7 2024, 12:41 AM · MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth
Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

any word on this one? in my personal experience, webauthn is pretty much unusable. I can't return to an existing wiki on another device reliably, and I can't log on a new wiki at all.

May 7 2024, 12:39 AM · MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth

Apr 29 2024

Tonymetz added a comment to T227237: Create PasswordCannotMatchEmail password policy.

thanks for the guidance I may take this one. I'll improve the docs if it's better suited for the tag. I appreciate the guidance.

Apr 29 2024, 10:31 PM · MediaWiki-Core-AuthManager
Tonymetz added a project to T227237: Create PasswordCannotMatchEmail password policy: good first task.
Apr 29 2024, 9:50 PM · MediaWiki-Core-AuthManager
Tonymetz added a watcher for good first task: Tonymetz.
Apr 29 2024, 6:04 PM
Tonymetz added a comment to T227237: Create PasswordCannotMatchEmail password policy.

@Reedy is this still relevant? It seems similar to includes/password/PasswordPolicyChecks.php L95 checkPasswordCannotBeSubstringInUsername()

Apr 29 2024, 5:30 AM · MediaWiki-Core-AuthManager
Tonymetz added a watcher for MediaWiki-extensions-Arrays: Tonymetz.
Apr 29 2024, 5:02 AM
Tonymetz added a watcher for MediaWiki-Email: Tonymetz.
Apr 29 2024, 5:01 AM
Tonymetz added a watcher for MediaWiki-Debian: Tonymetz.
Apr 29 2024, 5:01 AM
Tonymetz added a watcher for Mail: Tonymetz.
Apr 29 2024, 5:00 AM
Tonymetz added a watcher for Gender-Support: Tonymetz.
Apr 29 2024, 4:59 AM
Tonymetz added a watcher for events: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for Elasticsearch: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for doc.wikimedia.org: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for Developer Productivity: Tonymetz.
Apr 29 2024, 4:58 AM
Tonymetz added a watcher for Data-Services: Tonymetz.
Apr 29 2024, 4:57 AM
Tonymetz added a watcher for covid-19: Tonymetz.
Apr 29 2024, 4:54 AM
Tonymetz added a watcher for IPv6: Tonymetz.
Apr 29 2024, 4:50 AM

Apr 28 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Webauthn security tokens are not being passed to wikifunctions.org

Apr 28 2024, 5:34 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Apr 25 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

@taavi any updates on the webauthn tasks merge progress? Are we looking at another 6 weeks?

Apr 25 2024, 4:54 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Apr 19 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.
  1. it is a one-line change
  2. it is a back-port of code from the webauthn repo
  3. reedy & I recorded our testing procedure above with video and code samples
Apr 19 2024, 8:31 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

@Aklapper I don't appreciate the dismissive tone being used. I invested a lot of effort working together with Reedy to reproduce, debug & help formulate a fix. At the very least you could help clarify exactly what the next steps are here.

Apr 19 2024, 8:14 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

It seems the commit was made Mar 5 so it's been 6 weeks. Can you guess how many more weeks it is going to be?

Apr 19 2024, 4:53 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Reedy and I already got this fixed and he submitted a patch. So we're just waiting for it to get merged. What is blocking that?

Apr 19 2024, 4:49 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Can I ask what the blocker is?

Apr 19 2024, 4:31 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

any ETA on this one?

Apr 19 2024, 4:07 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Apr 9 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

There may be another variant of the issue when logging in on meta.wikipedia.org. It seems that the viable webauthn credential list is being filtered either by site or by login device before being presented to the browser. I get a different experience on different browsers.

Apr 9 2024, 6:58 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 26 2024

Tonymetz added a comment to T244088: Logging in at another wiki than WebAuth was set up fails.

during testing for T358771 we discovered that login also fails when logging in on the same wiki using a new device.

Mar 26 2024, 5:43 PM · MW-1.35-notes (1.35.0-wmf.28; 2020-04-14), MediaWiki-extensions-OATHAuth
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

what's a good way to track the launch status for this fix? i'm sorry I don't know too much about the deployment process

Mar 26 2024, 5:35 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 7 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

can I help testing out the change on the test env?

Mar 7 2024, 5:40 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 6 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

happy to help -- great partnership on this

Mar 6 2024, 2:11 AM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

yep cable works like hybrid

Mar 6 2024, 2:02 AM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

debug session showing how to fix

Mar 6 2024, 1:10 AM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

screenshot evidence. video inbound
{F42406516}

Mar 6 2024, 1:02 AM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

wow it worked!

Mar 6 2024, 1:02 AM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 5 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

https://github.com/wikimedia/mediawiki-extensions-WebAuthn/blob/979220702ab45fb4755ed45bd38cbbb05a411c22/resources/login.js#L3 in the repo

Mar 5 2024, 10:33 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

I can break into the login phase (using chrome devtools) at https://en.wikipedia.org/w/extensions/WebAuthn/resources/login.js L3 and reproduce the issue.

Mar 5 2024, 10:32 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

"windows-pc" -- this one is internal (windows hello / TPM)
"iphone" -- this one is iPhone Passkey (added via QR-code) . I think it's supposed to be "hybrid"

Mar 5 2024, 10:25 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Here's my list of tokens on wikimedia

Mar 5 2024, 10:22 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

I believe "HYBRID" is the one that supports the iPhone /passkey based login : https://web.dev/articles/passkey-registration

Mar 5 2024, 10:16 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

(i'm a bit new to webauthn) it seems that the site (wikipedia) sends a list of token public keys / token IDs to the browser to initiate token-based authentication.

Mar 5 2024, 10:04 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

That USB popup looks very Windows/Edge specific. I don't think the message is in our code, or anything we bring in via vendor.

Mar 5 2024, 9:58 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz updated the task description for T358771: Unable to login on iPhone with Passkey Enabled.
Mar 5 2024, 5:00 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

this bug is pretty serious. I'd like to disable 2-FA but i also want to help get it fixed. I'll be locked out of my account if something happens to my first login session

Mar 5 2024, 4:58 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

I'm blocked by another variant of this issue: login from a separate windows machine. I'm being prompted to "insert usb security key" but i have two passkeys registered : (1) from iphone and (1) from another windows machine. I would expect the option to pop a QR-CODE to proceed using iphone passkey

Mar 5 2024, 4:57 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security

Mar 1 2024

Tonymetz created T358824: Help Users Avoid Creating Duplicate Logins.
Mar 1 2024, 12:32 AM · MediaWiki-User-login-and-signup

Feb 29 2024

Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

if we have measurements of "Authentication process was interrupted " we could segment by user -agent or device to measure incidence of this issue.

Feb 29 2024, 8:37 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

video working experience using "show desktop site" on mobile safari

Feb 29 2024, 8:35 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Wonder if this is some variant of T244088: Logging in at another wiki than WebAuth was set up fails, due to the different mobile domain...

Feb 29 2024, 8:22 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz added a comment to T358771: Unable to login on iPhone with Passkey Enabled.

Some more context…

  1. I created two keys using Edge. (1) was a local key and (2) was the iPhone key (using QR code)
Feb 29 2024, 5:25 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security
Tonymetz created T358771: Unable to login on iPhone with Passkey Enabled.
Feb 29 2024, 2:53 PM · Patch-For-Review, Mobile, MediaWiki-extensions-OATHAuth, Security