Page MenuHomePhabricator

Add `bin/auth list-factors` and `bin/auth strip` to remove multi-factor auth
ClosedPublic

Authored by epriestley on Apr 30 2014, 11:57 AM.
Tags
None
Referenced Files
F14046021: D8909.id21166.diff
Wed, Nov 13, 5:19 PM
F14045752: D8909.id.diff
Wed, Nov 13, 10:25 AM
F14041014: D8909.diff
Mon, Nov 11, 3:13 PM
F14001949: D8909.diff
Fri, Oct 25, 1:31 PM
F13965725: D8909.id21166.diff
Oct 16 2024, 3:56 AM
Unknown Object (File)
Oct 13 2024, 9:17 PM
Unknown Object (File)
Sep 15 2024, 12:26 AM
Unknown Object (File)
Sep 12 2024, 9:26 AM
Subscribers

Details

Summary

Ref T4398. The major goals here is to let administrators strip auth factors in two cases:

  • A user lost their phone and needs access restored to their account; or
  • an install previously used an API-based factor like SMS, but want to stop supporting it (this isn't possible today).
Test Plan
  • Used bin/auth list-factors to show installed factors.
  • Used bin/auth strip with various mixtures of flags to selectively choose and strip factors from accounts.
  • Also ran bin/auth refresh to verify refreshing OAuth tokens works (small OAuth vs OAuth2 tweak).

Diff Detail

Repository
rP Phabricator
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

epriestley retitled this revision from to Add `bin/auth list-factors` and `bin/auth strip` to remove multi-factor auth.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Apr 30 2014, 5:39 PM
epriestley updated this revision to Diff 21166.

Closed by commit rP535cfa3ebebe (authored by @epriestley).