Page MenuHomePhabricator

Make external link/refresh use provider IDs, switch external account MFA to one-shot
ClosedPublic

Authored by epriestley on Feb 7 2019, 1:43 AM.
Tags
None
Referenced Files
F19937271: D20117.id.diff
Sun, Apr 12, 9:17 PM
F19934959: D20117.diff
Sat, Apr 11, 7:24 PM
F19880154: D20117.diff
Wed, Mar 18, 3:34 AM
F19880153: D20117.diff
Wed, Mar 18, 3:34 AM
F19810732: D20117.diff
Mar 3 2026, 9:01 PM
F19562397: D20117.diff
Jan 31 2026, 1:27 PM
F19562396: D20117.diff
Jan 31 2026, 1:27 PM
F19554309: D20117.id48130.diff
Jan 29 2026, 8:17 PM
Subscribers
None

Details

Summary

Depends on D20113. Ref T6703. Continue moving toward a future where multiple copies of a given type of provider may exist.

Switch MFA from session-MFA at the start to one-shot MFA at the actual link action.

Add one-shot MFA to the unlink action. This theoretically prevents an attacker from unlinking an account while you're getting coffee, registering alIce which they control, adding a copy of your profile picture, and then trying to trick you into writing a private note with your personal secrets or something.

Test Plan

Linked and unlinked accounts. Refreshed account. Unlinked, then registered a new account. Unlinked, then relinked to my old account.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable