Extension:OATHAuth

From MediaWiki.org
Jump to: navigation, search
This extension comes with MediaWiki 1.31 and above. Thus you do not have to download it again. However, you still need to follow the other instructions provided.
MediaWiki extensions manualManual:Extensions
Crystal Clear action run.svg
OATHAuth

Release status:Extension status stable

ImplementationTemplate:Extension#type User rights, Special page, Page action
DescriptionTemplate:Extension#description Provides two-factor authentication for logging in
Author(s)Template:Extension#username Ryan Lane
Latest versionTemplate:Extension#version Continuous updates
Compatibility policyCompatibility#mediawiki_extensions master
MediaWikiTemplate:Extension#mediawiki 1.27+
Database changesTemplate:Extension#needs-updatephp Yes
LicenseTemplate:Extension#license GNU General Public License 2.0 or later
Download
ParametersTemplate:Extension#parameters
  • $wgOATHAuthWindowRadius
  • $wgOATHAuthDatabase
  • $wgOATHAuthSecret
  • $wgOATHAuthAccountPrefix
Added rightsTemplate:Extension#rights
  • oathauth-enable
  • oathauth-api-all
Hooks usedTemplate:Extension#hook
AuthChangeFormFieldsManual:Hooks/AuthChangeFormFields
TwoFactorIsEnabled
LoadExtensionSchemaUpdatesManual:Hooks/LoadExtensionSchemaUpdates
GetPreferencesManual:Hooks/GetPreferences

Translate the OATHAuth extension if it is available at translatewiki.net

Check usage and version matrix.

IssuesPhabricator

Open tasks · Report a bug

The OATHAuth extension is a time-based one-time password (TOTP) implementation. It provides two-factor authentication via something you have (your phone or desktop client) and something you know (your user name/password). Client support is available for most feature phones, smartphones and desktops (see Client implementations). This extension has nothing to do with OAuth, which is a totally different protocol.

Installation[edit]

  • Download and place the file(s) in a directory called OATHAuth in your extensions/ folder.
  • Add the following code at the bottom of your LocalSettings.php:
    wfLoadExtension( 'OATHAuth' );
    
  • Run the update script which will automatically create the necessary database tables that this extension needs.
  • Configure as required.
  • YesY Done - Navigate to Special:Version on your wiki to verify that the extension is successfully installed.

To users running MediaWiki 1.26 or earlier:

The instructions above describe the new way of installing this extension using wfLoadExtension() If you need to install this extension on these earlier versions (MediaWiki 1.26 and earlier), instead of wfLoadExtension( 'OATHAuth' );, you need to use:

require_once "$IP/extensions/OATHAuth/OATHAuth.php";

Configuration[edit]

$wgOATHAuthWindowRadius
Defaults to "4". Controls ... TODO
$wgOATHAuthDatabase
Defauls to "false". Controls ... TODO
$wgOATHAuthSecret
Defauls to "false". Controls ... TODO
$wgOATHAuthAccountPrefix
Defauls to "false". Controls ... TODO

Usage[edit]

Granting access to enable OATHAuth[edit]

Users should be given access to the oathauth-enable user right so that they can enable it at Special:OATHAuth (a link to which appears at Special:Preferences).

$wgGroupPermissions['user']['oathauth-enable'] = true;

The above will grant all registered users access to enable OATHAuth.

Resetting a user token[edit]

In the event that a user both loses their token generator AND the recovery tokens; two-factor authentication may be removed from the user by deleting their row from the oathauth_users database table. A sysadmin with shell access may type on a command line cd /path/to/mediawiki/extensions/OATHAuth/maintenance/ and then execute php disableOATHAuthForUser.php "<username>" where <username> is the user to have 2FA disabled to have it disabled.

See also[edit]