-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Backup code text/download should include context #293
Comments
We can also include the name of .txt file in our documentation to help users find saved codes on their computer. |
The two-factor plugin has the following header for files:
|
Suggestion:
|
This is perhaps too much information for backup codes, and that username shouldn't feature in the output? |
The addition of the username comes from the issue description; I feel that the user experience improvement is better than the alternative. If someone has their 2FA backup codes leaked they've likely got bigger problems?
|
Currently the backup codes, when copied to clipboard or downloaded as a text file, contains literally only the comma-separated codes.
It would be better to include a little context with that text. At a minimum, a simple header such as:
Two-Factor backup codes for your wordpress.org account:
This would make it easier for users to search their computer/phone for codes in a recovery situation.
We could also consider including additional context like the date and username. Including the username could increase the likelihood of a bad actor misusing a misplaced file; I'm not sure if that's a significant issue.
The text was updated successfully, but these errors were encountered: