Automattic / Automattic/wp-openid-connect-server

2FA when users can register their own clients

Open
#49 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
PHP
Stars
44
Forks
13
PR merge metrics
No merged PRs in 30d

Description

When we reach the point of user registering their own client for whatever needs, we should 2FA them to be really sure about the intent, to prevent possible misuse of their account.

Also admin should have moderation control over clients being registered and only when approved, a registered client should go live.

Contributor guide

Open the contributing guide

Research direction

The issue names no files or tests. Start by locating the existing user client-registration flow and the admin controls for registered clients; define the 2FA and approval behavior before making changes. Done means self-registered clients require 2FA and remain inactive until an administrator approves them.

Written by the indexing model from the issue text.

Assessment

Tech stack
php, wordpress
Domain
authentication, authorization, backend
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.