Automattic / Automattic/wp-openid-connect-server
2FA when users can register their own clients
- Dominant language
- PHP
- Stars
- 44
- Forks
- 13
- PR merge metrics
- No merged PRs in 30d
Description
When we reach the point of user registering their own client for whatever needs, we should 2FA them to be really sure about the intent, to prevent possible misuse of their account.
Also admin should have moderation control over clients being registered and only when approved, a registered client should go live.
Contributor guide
Research direction
The issue names no files or tests. Start by locating the existing user client-registration flow and the admin controls for registered clients; define the 2FA and approval behavior before making changes. Done means self-registered clients require 2FA and remain inactive until an administrator approves them.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php, wordpress
- Domain
- authentication, authorization, backend
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100