VOOZH about

URL: https://phabricator.wikimedia.org/T423119

⇱ ⚓ T423119 FY25-26 Q4: Phase 2 of 2FA enforcement in Wikimedia production


Maniphest T423119

FY25-26 Q4: Phase 2 of 2FA enforcement in Wikimedia production
Closed, ResolvedPublic

Description

Per the timeline published on Meta-Wiki, in May 2026, the following groups will have 2FA enforced:

  • (only on private and fishbowl wikis)

Acceptance criteria

Pre-enforcement: (can be done well before)

  • WikimediaMessages contains relevant messages in form: and
  • is properly configured to address the newly-enforced groups (only for groups that are revoked by someone else than stewards)

Enforcement:

  • The listed groups can be assigned only to users with 2FA enabled
  • The listed groups are automatically revoked from members who don't have 2FA

Related Objects

Event Timeline

Comment Actions

Change #1281533 had a related patch set uploaded (by Alex.sanford; author: Alex.sanford):

[mediawiki/extensions/WikimediaMessages@master] Add messages related to mndatory 2FA for more groups

https://gerrit.wikimedia.org/r/1281533

Comment Actions

Change #1281533 abandoned by Alex.sanford:

[mediawiki/extensions/WikimediaMessages@master] Add messages related to mandatory 2FA for more groups

Reason:

Prevent accidental merge

https://gerrit.wikimedia.org/r/1281533

Comment Actions

Change #1281533 restored by Alex.sanford:

[mediawiki/extensions/WikimediaMessages@master] Add messages related to mandatory 2FA for more groups

https://gerrit.wikimedia.org/r/1281533

Comment Actions

Change #1281533 merged by jenkins-bot:

[mediawiki/extensions/WikimediaMessages@master] Add messages related to mandatory 2FA for more groups

https://gerrit.wikimedia.org/r/1281533

Comment Actions

Change #1283028 had a related patch set uploaded (by Alex.sanford; author: Alex.sanford):

[mediawiki/extensions/WikimediaMessages@wmf/1.47.0-wmf.1] Add messages related to mandatory 2FA for more groups

https://gerrit.wikimedia.org/r/1283028

Comment Actions

Change #1283028 merged by jenkins-bot:

[mediawiki/extensions/WikimediaMessages@wmf/1.47.0-wmf.1] Add messages related to mandatory 2FA for more groups

https://gerrit.wikimedia.org/r/1283028

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-06T13:13:20Z] <alexsanford@deploy1003> Started scap sync-world: Backport for [[gerrit:1283028|Add messages related to mandatory 2FA for more groups (T423119)]]

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-06T13:31:07Z] <alexsanford@deploy1003> alexsanford: Backport for [[gerrit:1283028|Add messages related to mandatory 2FA for more groups (T423119)]] synced to the testservers (see https://wikitech.wikimedia.org/wiki/Mwdebug). Changes can now be verified there.

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-06T13:44:14Z] <alexsanford@deploy1003> Finished scap sync-world: Backport for [[gerrit:1283028|Add messages related to mandatory 2FA for more groups (T423119)]] (duration: 30m 53s)

Comment Actions

Change #1285905 had a related patch set uploaded (by Alex.sanford; author: Alex.sanford):

[operations/mediawiki-config@master] Enforce 2FA requirements for phase 2 groups

https://gerrit.wikimedia.org/r/1285905

Comment Actions

Change #1286469 had a related patch set uploaded (by Alex.sanford; author: Alex.sanford):

[operations/mediawiki-config@master] Prepare $wgOATH2FARequiredGroupRemovalPages for phases 2 and 3

https://gerrit.wikimedia.org/r/1286469

Comment Actions

Change #1285905 merged by jenkins-bot:

[operations/mediawiki-config@master] Enforce 2FA requirements for phase 2 groups

https://gerrit.wikimedia.org/r/1285905

Comment Actions

Change #1286469 merged by jenkins-bot:

[operations/mediawiki-config@master] Prepare $wgOATH2FARequiredGroupRemovalPages for phases 2 and 3

https://gerrit.wikimedia.org/r/1286469

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-12T20:03:35Z] <alexsanford@deploy1003> Started scap sync-world: Backport for [[gerrit:1285905|Enforce 2FA requirements for phase 2 groups (T423119)]], [[gerrit:1286469|Prepare $wgOATH2FARequiredGroupRemovalPages for phases 2 and 3 (T423119 T423120)]]

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-12T20:05:31Z] <alexsanford@deploy1003> alexsanford: Backport for [[gerrit:1285905|Enforce 2FA requirements for phase 2 groups (T423119)]], [[gerrit:1286469|Prepare $wgOATH2FARequiredGroupRemovalPages for phases 2 and 3 (T423119 T423120)]] synced to the testservers (see https://wikitech.wikimedia.org/wiki/Mwdebug). Changes can now be verified there.

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-12T20:15:22Z] <alexsanford@deploy1003> Finished scap sync-world: Backport for [[gerrit:1285905|Enforce 2FA requirements for phase 2 groups (T423119)]], [[gerrit:1286469|Prepare $wgOATH2FARequiredGroupRemovalPages for phases 2 and 3 (T423119 T423120)]] (duration: 11m 47s)

Comment Actions

Change #1295039 had a related patch set uploaded (by Alex.sanford; author: Alex.sanford):

[operations/mediawiki-config@master] Add 2FA demotion config for phase 2 groups

https://gerrit.wikimedia.org/r/1295039

Comment Actions

Change #1295039 merged by jenkins-bot:

[operations/mediawiki-config@master] Add 2FA enforcement demotion config for phase 2 groups

https://gerrit.wikimedia.org/r/1295039

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-28T20:13:08Z] <stran@deploy1003> Started scap sync-world: Backport for [[gerrit:1291996|Replace deprecated Hooks::getInstance (T426981)]], [[gerrit:1294393|Permissions: Create wmf-officeit group on officewiki]], [[gerrit:1294229|Deploy IRS Direct Reporting feature to enwiki (T427369)]], [[gerrit:1295039|Add 2FA enforcement demotion config for phase 2 groups (T423119)]]

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-28T20:14:53Z] <stran@deploy1003> alexsanford, stran, catrope, dreamyjazz: Backport for [[gerrit:1291996|Replace deprecated Hooks::getInstance (T426981)]], [[gerrit:1294393|Permissions: Create wmf-officeit group on officewiki]], [[gerrit:1294229|Deploy IRS Direct Reporting feature to enwiki (T427369)]], [[gerrit:1295039|Add 2FA enforcement demotion config for phase 2 groups (T423119)]] synced to the testservers (see https://wikitech.

Comment Actions

Mentioned in SAL (#wikimedia-operations) [2026-05-28T20:22:16Z] <stran@deploy1003> Finished scap sync-world: Backport for [[gerrit:1291996|Replace deprecated Hooks::getInstance (T426981)]], [[gerrit:1294393|Permissions: Create wmf-officeit group on officewiki]], [[gerrit:1294229|Deploy IRS Direct Reporting feature to enwiki (T427369)]], [[gerrit:1295039|Add 2FA enforcement demotion config for phase 2 groups (T423119)]] (duration: 09m 07s)

ASanford-WMF claimed this task.
Comment Actions

Completed May 28

Content licensed under Creative Commons Attribution-ShareAlike (CC BY-SA) 4.0 unless otherwise noted; code licensed under GNU General Public License (GPL) 2.0 or later and other open source licenses. By using this site, you agree to the Terms of Use, Privacy Policy, and Code of Conduct. · Wikimedia Foundation · Privacy Policy · Code of Conduct · Terms of Use · Disclaimer · CC-BY-SA · GPL · Credits