Skip to content

Add personal data export and erasure support - #999

Closed
dknauss wants to merge 3 commits into
WordPress:masterfrom
dknauss:add/privacy-exporter-eraser
Closed

dknauss wants to merge 3 commits into
WordPress:masterfrom
dknauss:add/privacy-exporter-eraser

Conversation

@dknauss

@dknauss dknauss commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Adds personal data export and erasure support for Two-Factor.

The export describes stored data without exposing secrets or backup codes. Erasure clears temporary login data and tells the requester when credentials or settings are kept, including credentials for a turned-off method.

Closes #954

Tested: npm test (205 tests passed).

Open WordPress Playground Preview

@github-actions

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: dknauss <dpknauss@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

dknauss and others added 3 commits September 26, 2026 10:05
The plugin stores per-user authentication records in user meta but did
not hook into the WordPress personal data tools added in 4.9.6, so an
administrator handling an export or erasure request saw none of it.

Exporter reports what is stored without disclosing any of it: enabled
and primary methods, TOTP as configured rather than its secret, backup
codes as a remaining count rather than codes or hashes, a pending email
code by the time it was issued, and the failed-attempt records.

Eraser removes the incidental login records — login nonce, failed
attempt counter, rate-limit timestamp, password-reset flag, pending
email token, TOTP replay timestamp. Credentials are deliberately
retained and reported through items_retained: erasing them would turn
off the second factor on a live account without the account holder
asking for that. They are already removed when the account is deleted,
and on uninstall.

Providers contribute through two optional methods on the base class,
privacy_export_data() and privacy_eraser_user_meta_keys(), mirroring
the existing uninstall_user_meta_keys() pattern so core carries no
provider-specific logic.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The eraser removed `_two_factor_totp_last_successful_login` but nothing
asserted it. Verified the test catches a regression by returning an
empty array from Two_Factor_Totp::privacy_eraser_user_meta_keys() and
watching it fail before restoring.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@dknauss
dknauss force-pushed the add/privacy-exporter-eraser branch from 4fe4213 to c43c623 Compare September 26, 2026 16:05
@masteradhoc

Copy link
Copy Markdown
Collaborator

Thank you @dknauss for the PR, but there already has been one opened today (see #997). I'll have to close this as duplicate as its anyhow nearly identical.

Would you mind giving your feedback there instead?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Privacy: register a personal data exporter and eraser

2 participants