Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Making WHATWG a 2FA organization #155

Open
annevk opened this issue Dec 22, 2019 · 2 comments
Open

Making WHATWG a 2FA organization #155

annevk opened this issue Dec 22, 2019 · 2 comments

Comments

@annevk
Copy link
Member

annevk commented Dec 22, 2019

I think it would be nice if we enforced 2FA for the entire organization. That way there's less manual checking when giving people more power and would also guard the organization against people lowering their amount of protection.

Given https://github.com/orgs/whatwg/people?query=two-factor%3Adisabled we'd need to do a decent amount of outreach first, but I'm willing to drive that if there's support for doing this.

See also #113.

@domfarolino
Copy link
Member

Does https://github.com/orgs/whatwg/people?query=two-factor%3Adisabled only show correct results for owners or something? I have 2FA enabled, and from my view, Domenic, yourself, and I are all on that list, which isn't correct (for at least me, and presumably you two).

@domenic
Copy link
Member

domenic commented Dec 23, 2019

That... appears to be something like what's happening. I can reproduce in incognito mode, where (I would guess) it is just showing everyone in the organization. Also, some of the UI---including the UI for filtering by 2FA---is disabled in incognito.

I guess the idea is non-owners shouldn't be able to see peoples' security status. But IMO it's a GitHub bug that the search field still can be populated with "two-factor:disabled" with no warning about what's happening.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

3 participants