https://bugzilla.wikimedia.org/show_bug.cgi?id=53197

       Web browser: ---
            Bug ID: 53197
           Summary: OATH should use $wgSecureLogin (or have it's own
                    similar variable)
           Product: MediaWiki extensions
           Version: master
          Hardware: All
                OS: All
            Status: NEW
          Severity: normal
          Priority: Unprioritized
         Component: OATHAuth
          Assignee: [email protected]
          Reporter: [email protected]
    Classification: Unclassified
   Mobile Platform: ---

The TOTP RFC recommends all communications (especially those involving the
secret key) be over TLS. I recommend using $wgSecureLogin as an indicator of
whether communications should be forced over HTTPS.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to