Authentication checkers

From WickedGov Meta-Wiki
Revision as of 11:10, 15 April 2025 by Luke (talk | contribs) (Marked this version for translation)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Authentication checkers are trusted users with the ability to check whether a user has two-factor authentication enabled. These checks are centrally performed on Meta-Wiki and logged in a private log visible only to Stewards.

Criteria for checks[edit | edit source]

In general, two-factor authentication checks should only be performed when the following criteria are met:

  • The checked user holds or is requesting a permission that requires two-factor authentication.
  • The permission is held or requested on a wiki where the checker has authority to manage such access.
    • For example, a checker who is a bureaucrat on wiki A, but not on wiki B, should not perform checks on wiki B's interface administrators.

Appointment[edit | edit source]

Requests for this permission may be placed on Stewards/Requests/Global permissions. In general, requests will be approved if the following criteria are met:

  • The user is a bureaucrat on a WickedGov wiki or has another compelling reason to have access to users' two-factor authentication status.
  • The user has identified to the WickedGov office and appears on the identification noticeboard.
  • The user is trusted not to misuse the access.

Removal[edit | edit source]

Authentication checker access will be removed by a Steward in the following cases:

  • The user seriously misuses the access by making unnecessary or inappropriate checks.
  • The user no longer has a good reason to access 2FA status (for example, if the user is no longer a bureaucrat).