WordPress / WordPress/two-factor

Woocommerce 2FA settings implementation

Open
#704 8 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
PHP
Stars
825
Forks
187
Avg merge
2d 11h
Merged PRs (30d)
17

Description

Is your enhancement related to a problem? Please describe.

EDIT: added form save code (copy from Core class), to complete proof of concept.

I created a quick Woocommerce 2FA account settings implementation. The form save functionality needs to be implemented still, but I wanted to drop my idea here.

With the following code the form renders well and the [verify totp], [deactivate totp], [generate codes] and [download codes] buttons function.

Next, I will seperate the user profile admin saving function from the action hook, and make sure both the front end and backend will use the same save function. In theory that should be enough to have a crude(?) initial separation of the admin settings.

As the dummy and U2F provider are shown on front end I add a filter to remove these from the front end settings.

Proposed Solution
  • Add Two_Factor_Woo class

    • Endpoints
    • Filter providers
    • Generate form (using Core)
    • Save form function (using new form_save Core)
    • Enqueue Javascript
  • Adjust Two_Factor_Core class

    • Add seperate form_save function
    • Rewrite save user options to use new form_save
  • Add Two_Factor_Woo.js

    • Two step login logic javascript for Woocommerce
Proof of Concept
-edit- see plugin repo in comment below

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the proposed Two_Factor_Woo and Two_Factor_Core changes, including the shared form-save flow, then inspect Two_Factor_Woo.js for the WooCommerce login behavior. Done means WooCommerce settings render and save correctly on the frontend and backend, with the intended providers filtered and the listed TOTP actions working.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, php
Domain
authentication, backend, frontend
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.