Skip to content

Hooks to support requesting 2FA for plugins extending two-factor core functionality #644

@jeffpaul

Description

@jeffpaul

Is your enhancement related to a problem? Please describe.

There are potential cases of other plugins, or perhaps custom site functionality, where they might want to leverage the two-factor core plugin functionality to trigger a re-auth of a specific users 2FA credentials. One example here would be a site with an expected high traffic event (e.g. Cyber Monday ad, Super Bowl ad) or perhaps becoming a larger target for hacks and improper publishing (e.g. news org during a national election) wherein they want to force someone trying to update or publish new content to go through re-auth via 2FA to ensure that the author and content being updated/published is done so by a properly credentialed user (versus someone who perhaps gained access to someone's machine to try and update/publish nefarious content).

Proposed Solution

Well documented hooks to expose portions of the 2FA auth flow from places within the WP Admin or site front end as well as some sample code snippets feels like a solid option to support this sort of compatibility/extension of the two-factor plugin.

Designs

No response

Describe alternatives you've considered

No response

Please confirm that you have searched existing issues in this repository.

Yes

Metadata

Metadata

Assignees

No one assigned

    Labels

    CompatibilityCompatibility with other plugins, Core, back-compat

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions