Skip to content

2FA User Interfaces (authentication workflow) #5587

Closed
@nlhkabu

Description

@nlhkabu

Proposed UI for 2FA login workflow (swap purple for PyPI blue... and voila!):

Screenshot from 2019-03-18 20-36-17

Screenshot from 2019-03-18 12-04-14

Screenshot from 2019-03-18 12-04-59

Notes:

  1. two tabs will only be shown if user has chosen to setup both methods. The 'default' method (i.e. default tab) will be defined by the user in the admin
  2. 'Get help' links will link through to appropriate help section (see 2FA/multifactor auth: policy on requiring recovery codes #5586)

@woodruffw - I decided that it would be better to separate the recovery codes from the key authentication (e.g. not use the same form, as we had discussed), because they are not equal in effectiveness. A recovery code can only be used once, and is bypassing the 2FA process - for this reason, we want to discourage their use to only 'emergency' situations. My concern with using the same form as the key input, is that users will believe these methods are equal in value.


Screenshot Required: This issue will require an update to the visual design of the site. To help our team give you faster feedback, include a screenshot in your Pull Request.

Metadata

Metadata

Assignees

Labels

UX/UIdesign, user experience, user interface

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions