Add personal data exporter and eraser - #997
faisalahammad wants to merge 1 commit into
Conversation
Register the plugin with the WordPress personal data export and erasure tools. - Two_Factor_Core registers both privacy filters and implements the callbacks, keeping the data provider-agnostic. - Providers contribute via two optional base methods on Two_Factor_Provider: privacy_export_data() and privacy_eraser_user_meta_keys(), mirroring the existing uninstall_user_meta_keys() pattern. - The eraser removes short-lived records (login nonce, rate limit counters, email tokens, TOTP replay marker) and keeps credentials (TOTP secret, backup codes), reporting them as retained so the second factor stays active on the account. - Exports never include secret material: the TOTP key, hashed email tokens and backup codes stay out of the payload. - Tests cover the export contents, the erasure behavior, and that no secret material appears in the export payload. Fixes WordPress#954
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
|
Before we start reviewing. @faisalahammad would you mind changing all versions to 0.18.0 as 0.17.0 is already finalized? |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Address the incomplete export of disabled providers and clarify the email timestamp’s accuracy.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds WordPress personal-data export and erasure support for Two-Factor authentication data.
Changes:
- Registers privacy exporter and eraser callbacks.
- Adds provider-specific privacy methods.
- Exports non-secret metadata and removes short-lived records.
- Adds comprehensive PHPUnit coverage.
| File | Reviewed changes |
|---|---|
tests/providers/class-two-factor-totp.php |
Tests TOTP privacy behavior. |
tests/providers/class-two-factor-provider.php |
Tests base provider privacy methods. |
tests/providers/class-two-factor-email.php |
Tests email privacy behavior. |
tests/providers/class-two-factor-backup-codes.php |
Tests recovery-code export behavior. |
tests/class-two-factor-core.php |
Tests core privacy behavior and secret exclusion. |
providers/class-two-factor-totp.php |
Handles TOTP export and replay-marker erasure. |
providers/class-two-factor-provider.php |
Adds provider privacy extension methods. |
providers/class-two-factor-email.php |
Handles email metadata export and token erasure. |
providers/class-two-factor-backup-codes.php |
Exports remaining recovery-code counts. |
class-two-factor-core.php |
Implements privacy registration, export, and erasure. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| foreach ( self::get_providers() as $provider ) { | ||
| $provider_data = $provider->privacy_export_data( $user ); |
|
Review comment, requested by @masteradhoc:
|

What?
Registers the plugin with the WordPress personal data export and erasure tools (Tools > Export Personal Data and Tools > Erase Personal Data). Users can request a copy of their two-factor data, and site admins can clear login artifacts for a user.
Fixes #954
Why?
The plugin stores per-user authentication data (enabled methods, failed login counters, one-time tokens, TOTP replay markers) but hooks into neither privacy tool. None of it shows up in a personal data export, and none of it is removed on erasure, so sites honoring data requests have to clean up user meta by hand.
How?
Two_Factor_Coreregisters thewp_privacy_personal_data_exportersandwp_privacy_personal_data_erasersfilters and implements both callbacks. The export is one "Two Factor Authentication" group with the enabled methods, primary method, failed login attempts, and the last failed login time.Two_Factor_Provider, mirroring the existinguninstall_user_meta_keys()pattern:privacy_export_data( $user )returns display rows: TOTP shows "Configured" plus the last successful login, Email shows when a code was last sent, Backup Codes shows the remaining code count. Third-party providers get the same extension path without core knowing their meta keys.privacy_eraser_user_meta_keys()lists the short-lived keys each provider wants erased.items_retainedwith a message explaining they are removed when the account itself is deleted, so erasure cannot silently strip the second factor from a live account.Testing Instructions
Automated:
npm testruns the new PHPUnit tests covering the export contents, the erasure behavior, and that no secret material appears in the export payload.Manual:
npm install && npm run build && npm run env start.Changelog Entry
Added - Register a personal data exporter and eraser with the WordPress privacy tools.