-
Notifications
You must be signed in to change notification settings - Fork 995
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Define manual account recovery process #5758
Comments
I just enabled 2FA and was looking for recovery codes, so I'm particularly interested in this process. I have a mild preference for having actual codes vs the manual process, just because N days is a long time to wait. That's particularly important if for some reason you need to hurry up and make a release (e.g. CVE in your library). I mean, hopefully you have several people if your project is that important, but.... |
Hi @waynew thanks for your feedback. To be clear, our intention is to also offer recovery codes. However, users can choose not to enable these. Manual account recovery is therefore limited to circumstances when: a) a user has lost their recovery codes, or |
Implementing #5866 will help a bit with this as well. |
I've lost my authenticator app... and I didn't read about creating the usb method too... Am I in trouble? I really need to access my account. |
@lasote can you please open a new ticket for this? An admin can then contact you. |
Please file an issue at https://github.com/pypa/pypi-support/issues |
Possibly now superseded by pypi/support#796 ? |
Closing this in favor of #11787. |
With the introduction of two factor authentication, we have decided that the PyPI admins will support manual account recovery, in addition to optional recovery codes. I have opened this ticket to discuss and define this policy, and address the questions:
There has already been some discussion on this issue in #5586:
from @ewdurbin:
from @rsyring:
The text was updated successfully, but these errors were encountered: