Skip to content

Add personal data exporter and eraser - #997

Open
faisalahammad wants to merge 1 commit into
WordPress:masterfrom
faisalahammad:feature/954-privacy-exporter-eraser
Open

faisalahammad wants to merge 1 commit into
WordPress:masterfrom
faisalahammad:feature/954-privacy-exporter-eraser

Conversation

@faisalahammad

@faisalahammad faisalahammad commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

What?

Registers the plugin with the WordPress personal data export and erasure tools (Tools > Export Personal Data and Tools > Erase Personal Data). Users can request a copy of their two-factor data, and site admins can clear login artifacts for a user.

Fixes #954

Why?

The plugin stores per-user authentication data (enabled methods, failed login counters, one-time tokens, TOTP replay markers) but hooks into neither privacy tool. None of it shows up in a personal data export, and none of it is removed on erasure, so sites honoring data requests have to clean up user meta by hand.

How?

  • Two_Factor_Core registers the wp_privacy_personal_data_exporters and wp_privacy_personal_data_erasers filters and implements both callbacks. The export is one "Two Factor Authentication" group with the enabled methods, primary method, failed login attempts, and the last failed login time.
  • Providers contribute their own data through two optional methods on Two_Factor_Provider, mirroring the existing uninstall_user_meta_keys() pattern:
    • privacy_export_data( $user ) returns display rows: TOTP shows "Configured" plus the last successful login, Email shows when a code was last sent, Backup Codes shows the remaining code count. Third-party providers get the same extension path without core knowing their meta keys.
    • privacy_eraser_user_meta_keys() lists the short-lived keys each provider wants erased.
  • The eraser deletes short-lived records (login nonce, rate limit counters, failed attempt count, password reset flag, email token and its timestamp, TOTP last successful login) and deliberately keeps credentials (TOTP secret, backup code hashes, enabled and primary provider). Retained items are reported via items_retained with a message explaining they are removed when the account itself is deleted, so erasure cannot silently strip the second factor from a live account.
  • Exports never include secret material: the TOTP key, hashed email tokens, and backup codes are verified absent from the payload by dedicated tests.

Testing Instructions

Automated: npm test runs the new PHPUnit tests covering the export contents, the erasure behavior, and that no secret material appears in the export payload.

Manual:

  1. Build and start the dev environment: npm install && npm run build && npm run env start.
  2. Edit a test user and enable Email, TOTP, and Backup Codes under "Two-Factor Options".
  3. Generate a backup code set and configure TOTP so all three providers have data.
  4. Go to Tools > Export Personal Data, enter the test user's email, and run the export. The download contains a "Two Factor Authentication" group listing the enabled methods, the primary method, failed login attempts, the TOTP status with last successful login, the email code send time, and the remaining backup code count. No TOTP secret, tokens, or codes appear anywhere in the file.
  5. Go to Tools > Erase Personal Data, enter the same email, and run erasure. The result shows removed and retained counts, with a message that credentials were kept.
  6. Confirm the test user can still log in with the existing TOTP secret and backup codes, and that any in-flight 2FA prompt was invalidated by the erasure.
  7. Delete the test user and confirm the remaining two-factor user meta goes with the account.

Changelog Entry

Added - Register a personal data exporter and eraser with the WordPress privacy tools.

Open WordPress Playground Preview

Register the plugin with the WordPress personal data export and
erasure tools.

- Two_Factor_Core registers both privacy filters and implements the
  callbacks, keeping the data provider-agnostic.
- Providers contribute via two optional base methods on
  Two_Factor_Provider: privacy_export_data() and
  privacy_eraser_user_meta_keys(), mirroring the existing
  uninstall_user_meta_keys() pattern.
- The eraser removes short-lived records (login nonce, rate limit
  counters, email tokens, TOTP replay marker) and keeps credentials
  (TOTP secret, backup codes), reporting them as retained so the
  second factor stays active on the account.
- Exports never include secret material: the TOTP key, hashed email
  tokens and backup codes stay out of the payload.
- Tests cover the export contents, the erasure behavior, and that no
  secret material appears in the export payload.

Fixes WordPress#954
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: faisalahammad <faisalahammad@git.wordpress.org>
Co-authored-by: masteradhoc <masteradhoc@git.wordpress.org>
Co-authored-by: dknauss <dpknauss@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@masteradhoc

Copy link
Copy Markdown
Collaborator

Before we start reviewing. @faisalahammad would you mind changing all versions to 0.18.0 as 0.17.0 is already finalized?

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the incomplete export of disabled providers and clarify the email timestamp’s accuracy.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds WordPress personal-data export and erasure support for Two-Factor authentication data.

Changes:

  • Registers privacy exporter and eraser callbacks.
  • Adds provider-specific privacy methods.
  • Exports non-secret metadata and removes short-lived records.
  • Adds comprehensive PHPUnit coverage.
File Reviewed changes
tests/​providers/​class-two-factor-totp.php Tests TOTP privacy behavior.
tests/​providers/​class-two-factor-provider.php Tests base provider privacy methods.
tests/​providers/​class-two-factor-email.php Tests email privacy behavior.
tests/​providers/​class-two-factor-backup-codes.php Tests recovery-code export behavior.
tests/​class-two-factor-core.php Tests core privacy behavior and secret exclusion.
providers/​class-two-factor-totp.php Handles TOTP export and replay-marker erasure.
providers/​class-two-factor-provider.php Adds provider privacy extension methods.
providers/​class-two-factor-email.php Handles email metadata export and token erasure.
providers/​class-two-factor-backup-codes.php Exports remaining recovery-code counts.
class-two-factor-core.php Implements privacy registration, export, and erasure.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread class-two-factor-core.php
Comment on lines +3063 to +3064
foreach ( self::get_providers() as $provider ) {
$provider_data = $provider->privacy_export_data( $user );
@dknauss

dknauss commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review comment, requested by @masteradhoc:

  • 🟢 Retaining 2FA credentials during erasure. This is good because WordPress’s erasure tool only erases user data; it doesn’t delete the user account, and removing 2FA credentials could leave the account protected only by its password.
  • 🟢 Provider-specific tests alongside each provider are good.
  • 🔴 The privacy callbacks skip providers that are disabled site-wide. Both use get_providers(), which applies the site-wide provider filter. If a provider is disabled there, its provider-specific data is omitted from exports and its erasure keys are skipped, leaving that metadata on the account. (Confirmed with runtime testing.)
  • 🔴 Erasure removes TOTP replay protection. A code that was accepted once and rejected when reused will be accepted again after erasure if this all happens quickly enough. Extremely unlikely as an achievable exploit, but it exposes an avoidable weakening of replay protection in the original design in Privacy: register a personal data exporter and eraser #954. The eraser deletes the record that prevents reuse while keeping the secret. That record should remain, as it can still block replay. Fix: keep the replay marker alongside the secret and disclose both as retained security data. (Discovered and confirmed with adversarial testing.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Privacy: register a personal data exporter and eraser

4 participants