Help:Two-factor authentication/sd: Difference between revisions
Content deleted Content added
Updating to match new version of source page |
Updating to match new version of source page |
||
(24 intermediate revisions by the same user not shown) | |||
Line 18:
<div lang="en" dir="ltr" class="mw-content-ltr">
Two-factor authentication on Wikimedia is currently experimental and optional (with some exceptions). Enrollment requires <code>(oathauth-enable)</code> access, currently in production testing with [[Special:MyLanguage/Administrators|administrators]] (and users with admin-like permissions like [[Special:MyLanguage/interface editors|interface editors]]), [[Special:MyLanguage/bureaucrats|bureaucrats]], [[Special:MyLanguage/Checkuser policy|checkusers]], [[Special:MyLanguage/Oversight policy|oversighters]], [[Special:MyLanguage/Stewards|stewards]], [[Special:MyLanguage/Global_permissions#Abuse_filter|edit filter managers]] and the [[Special:GlobalUsers/oathauth-tester|OATH-testers global group]].
</div>▼
</div>
<span id="Mandatory_use_user_groups"></span>
=== هدايتي واپرائيندڙ گروپ ===
* <span lang="en" dir="ltr" class="mw-content-ltr">[[:Category:
* <span lang="en" dir="ltr" class="mw-content-ltr">May 2025 announcement: [[Special:MyLanguage/Mandatory two-factor authentication for users with some extended rights|Mandatory two-factor authentication for users with some extended rights]]</span>
▲* [[:Category:Global user groups that require two-factor authentication|Groups requiring two-factor authentication]]
</div>▼
<span id="Enabling_two-factor_authentication"></span>
Line 35 ⟶ 29:
* <span lang="en" dir="ltr" class="mw-content-ltr">Have <code>(oathauth-enable)</code> access (by default, available to administrators, bureaucrats, suppressors, check users and other privileged user groups)</span>
* <span lang="en" dir="ltr" class="mw-content-ltr">Have or install a [[:w:en:Time-based One-time Password Algorithm|Time-based One-time Password Algorithm]] (TOTP) client. For most users, this will be a phone or tablet application.
** <span lang="en" dir="ltr" class="mw-content-ltr">Open-source: [https://github.com/beemdevelopment/Aegis Aegis] (Android, F-Droid), [https://freeotp.github.io/ FreeOTP] (Android, F-Droid, iOS), [https://github.com/
** <span lang="en" dir="ltr" class="mw-content-ltr">Closed-source:
** <span lang="en" dir="ltr" class="mw-content-ltr">[[:w:en:
** <span lang="en" dir="ltr" class="mw-content-ltr">You can also use a desktop client such as the [https://www.nongnu.org/oath-toolkit/ OATH Toolkit] (Linux, macOS via Homebrew), or [https://github.com/winauth/winauth WinAuth] (Windows). Keep in mind that if you log in from the computer used to generate TOTP codes, this approach does not protect your account if an attacker gains access to your computer.</span>
** <span lang="en" dir="ltr" class="mw-content-ltr">Password managers such as
* <span lang="en" dir="ltr" class="mw-content-ltr">Go to [[Special:OATH]] '''on the project you hold one of the above rights on''' (this link is also available from your [[Special:Preferences#mw-prefsection-personal|preferences]]).
* <span lang="en" dir="ltr" class="mw-content-ltr">[[Special:OATH]] presents you with a [[{{lwp|QR code}}|QR code]] containing the '''Two-factor account name''' and '''Two-factor secret key.''' This is needed to pair your client with the server.</span>
* <span lang="en" dir="ltr" class="mw-content-ltr">Scan the QR code with, or enter the two-factor account name and key into, your TOTP client.</span>
* <span lang="en" dir="ltr" class="mw-content-ltr">Enter the authentication code from your TOTP client into the OATH screen to complete the enrollment.</span>
{{Caution|1=<span lang="en" dir="ltr" class="mw-content-ltr">WARNING: You will also be presented with a series of 10 one-time
{{clear}}
<span id="Logging_in"></span>
== لاگِ اِن ٿيڻ ==
[[{{lm|TOTP login|png}}|thumb|لاگِ اِن اِسِڪِرين]]
<div lang="en" dir="ltr" class="mw-content-ltr">
* Provide your username and password, and submit as before.
* Enter in a one-time six digit authentication code as provided by the TOTP client. Note: This code changes about every thirty seconds. If your code keeps getting rejected, check that the time on your device where your auth app is installed is correct.
</div>
Line 84 ⟶ 76:
</div>
{{clear}}
<span id="Disabling_two-factor_authentication"></span>
== ٻہ-عنصر جي تصديق غير فعال ڪرڻ ==
Line 94 ⟶ 85:
* <span lang="en" dir="ltr" class="mw-content-ltr">On the <u>disable two-factor authentication</u> page, use your authentication device to generate a code to complete the process.</span>
<div class="mw-translate-fuzzy">
▲<span id="Scratch_codes"></span>
== اِسڪريچ ڪوڊَ ==
▲</div>
[[{{lm|Enroll-Step3|png}}|thumb|<span lang="en" dir="ltr" class="mw-content-ltr">OATH example
<div lang="en" dir="ltr" class="mw-content-ltr">
When enrolling in two-factor authentication, you will be provided with a list of ten one-time
</div>
Line 107 ⟶ 99:
<div lang="en" dir="ltr" class="mw-content-ltr">
This may require '''two'''
</div>
Line 119 ⟶ 111:
<div lang="en" dir="ltr" class="mw-content-ltr">
You will need access to the
</div>
<div lang="en" dir="ltr" class="mw-content-ltr">
* You need to be logged in. If you are not already logged in, this will require use of a
* Visit [[Special:OATH]] and use a different
</div>
<div lang="en" dir="ltr" class="mw-content-ltr">
If you don't have enough
</div>
<div lang="en" dir="ltr" class="mw-content-ltr">
See [[wikitech:Password and 2FA reset#For users]] for instructions on requesting 2FA removal for your [[mw:Special:MyLanguage/Developer account|Developer account]].
</div>
Line 140 ⟶ 132:
<div lang="en" dir="ltr" class="mw-content-ltr">
Please note, most of the directions on this page are specific to the TOTP method. The [[{{lwp|WebAuthn}}|WebAuthn]] method is more experimental and currently has no recovery options (cf. [[phab:T244348|related developer task]]). WebAuthn has a known issue that you must make future logons on the same project that you initiate it from ([[phab:T244088|tracking task]]). WebAuthn is not currently available for use via mobile apps ([[phab:T230043|T230043]]).
▲</div>
<span id="See_also"></span>
Line 147 ⟶ 139:
<div lang="en" dir="ltr" class="mw-content-ltr">
* The [[:w:en:Multi-factor authentication|concept of multi-factor authentication]] in the
* [https://phabricator.wikimedia.org/tag/mediawiki-extensions-oathauth Known bugs and requested improvements] of Wikimedia's two-factor authentication are collaborated on and tracked in Phabricator
* [[mw:Special:MyLanguage/Extension:OATHAuth|OATHAuth]] is the MediaWiki extension used for this functionality
Line 154 ⟶ 146:
</div>
{{user groups}}
[[Category:MediaWiki extensions{{#translation:}}|Email confirmation]]▼
[[Category:Handbook Wikimedia-specific]]
|