Google Authenticator – WordPress 外掛
文章推薦指數: 80 %
Google Authenticator. 由Ivan Kruchkoff 開發. 這個外掛尚無繁體中文本地化版本。
請協助這個外掛完成本地化!
關於WordPress關於WordPressWordPress.org台灣繁體中文線上說明技術支援意見反應搜尋登入註冊
通知
跳至主要內容 WordPress.orgTaiwan正體中文
ToggleMenu
詳細資料
使用者評論
安裝方式
技術支援
開發資訊
外掛說明
TheGoogleAuthenticatorpluginforWordPressgivesyoutwo-factorauthenticationusingtheGoogleAuthenticatorappforAndroid/iPhone/Blackberry.
Ifyouaresecurityaware,youmayalreadyhavetheGoogleAuthenticatorappinstalledonyoursmartphone,usingitfortwo-factorauthenticationonGmail/Dropbox/Lastpass/Amazonetc.
Thetwo-factorauthenticationrequirementcanbeenabledonaper-userbasis.Youcouldenableitforyouradministratoraccount,butloginasusualwithlessprivilegedaccounts.
IfYouneedtomaintainyourblogusinganAndroid/iPhoneapp,oranyothersoftwareusingtheXMLRPCinterface,youcanenabletheApppasswordfeatureinthisplugin,
butpleasenotethatenablingtheApppasswordfeaturewillmakeyourbloglesssecure.
Credits
Thanksto:
PawełNowackiforthePolishtranslation
FabioZumbiforthePortuguesetranslation
GuidoSchalkxfortheDutchtranslation.
Henrik.Schackforwriting/maintainingversions0.20through0.48
TobiasBäthgeforhiscoderewriteandGermantranslation.
PascaldeBruijnforhis“relaxedmode”idea.
DanielWerlforhisusabilitytips.
DionHulseforhisbugfixes.
AldoLatinoforhisItaliantranslation.
KaijiaFengforhisSimplifiedChinesetranslation.
AlexConchaforhissecuritytips.
JeromeEtienneforhisjquery-qrcodeplugin.
SébastienPrunierforhisSpanishandFrenchtranslation.
螢幕擷圖
Theenhancedlog-inbox.GoogleAuthenticatorsectionontheProfileandPersonaloptionspage.QRcodeontheProfileandPersonaloptionspage.GoogleAuthenticatorapponAndroid
安裝方式
MakesureyourwebhostiscapableofprovidingaccuratetimeinformationforPHP/WordPress,ie.makesureaNTPdaemonisrunningontheserver.
Installandactivatetheplugin.
EnteradescriptionontheUsers->ProfileandPersonaloptionspage,intheGoogleAuthenticatorsection.
ScanthegeneratedQRcodewithyourphone,orenterthesecretmanually,remembertopickthetimebasedone.
Youmayalsowanttowritedownthesecretonapieceofpaperandstoreitinasafeplace.
RemembertohittheUpdateprofilebuttonatthebottomofthepagebeforeleavingthePersonaloptionspage.
That’sit,yourWordPressblogisnowalittlemoresecure.
常見問題集
CanIuseGoogleAuthenticatorforWordPresswiththeAndroid/iPhoneappsforWordPress?
Yes,youcanenabletheApppasswordfeaturetomakethatpossible,butnoticethattheXMLRPCinterfaceisn’tprotectedbytwo-factorauthentication,onlyalongpassword.
Iwanttoupdatethesecret,shouldIjustscanthenewQRcodeaftercreatinganewsecret?
No,you’llhavetodeletetheexistingaccountfromtheGoogleAuthenticatorapponyoursmartphonebeforeyouscanthenewQRcode,thatisunlessyouchangethedescriptionaswell.
Iamunabletologinusingthisplugin,what’swrong?
TheGoogleAuthenticatorverificationcodesaretimebased,soit’scrucialthattheclockinyourphoneisaccurateandinsyncwiththeclockontheserverwhereyourWordPressinstallationishosted.
IfyouhaveanAndroidphone,youcanuseanapplikeClockSynctosetyourclockincaseyourCellproviderdoesn’tprovideaccuratetimeinformation
Anotheroptionistoenable“relaxedmode”inthesettingsfortheplugin,thiswillenablemorevalidcodesbyallowinguptoa4min.timedriftineachdirection.
IhaveseveralusersonmyWordPressinstallation,isthatasupportedconfiguration?
Yes,eachuserhashisownGoogleAuthenticatorsettings.
DuringinstallationIforgotthethingaboutmakingsuremywebhostiscapableofprovidingaccuratetimeinformation,I’mnowunabletologin,pleasehelp.
IfyouhaveSSHorFTPaccesstoyourwebhostingaccount,youcanmanuallydeletethepluginfromyourWordPressinstallation,
justdeletethewp-content/plugins/google-authenticatordirectory,andyou’llbeabletologinusingusername/passwordagain.
Idon’townaSmartphone,isn’tthereanotherwaytogeneratethesesecretcodes?
Yes,thereisawebbasedversionhere:https://gauth.apps.gbraad.nl/
Githubprojecthere:https://github.com/gbraad/gauth
CanIcreatebackupcodes?
No,butifyou’reusinganAndroidsmartphoneyoucanreplacetheGoogleAuthenticatorappwithAuthenticatorPlus.
It’sareallyniceappthatcanimportyourexistingsettings,syncbetweendevicesandbackup/restoreusingyoursd-card.
It’snotafreeapp,butit’swellworththemoney.
Anyknownincompatabilities?
Yes,theMan-in-the-middleattack/replaydetectioncodeisn’tcompatiblewiththetest/setupmodeinthe“Stopspammerregistrationplugin”,
pleaseremembertoremovethe“Checkcredentialsonallloginattempts”checkmarkbeforeinstallingmyplugin.
使用者評論
Doeswhatitpromises.Waseasytoinstall.Hopefullywegetupdates...
Itisastraightforwardtoolanddoeswhatitsays.Veryeasytouseandsetup.
Thankyou.
IusethepluginonWordPress5.7.1anditworks.
ATTENTION:
TheprogramcurrentlydoesnotworktogetherwiththeWPSHideLoginpluginifyouusethe"TwoScreenSignin"option.
Worksgreatinnativewp-login.phpform,butotherformsthroughacriticalsiteerrorifyouattempttologintoauserthathas2faenabled.
Namelythewoocommerceloginform,inascenariowhere2faisinaseperatepagenotthesameform.
Iappreciatethedevwork,andkeepupthegoodwork,butminorissueslikeareabigdealinproductionsites.Botsaloneattemptingtologincanfillerrorlogrealquick.
thispluginworksperfectly,I’veuseditonmanysites.
Ilikethispluginbecauseitissimpleandnotcreatingfailedlogineventlikethe2FAoptionfromWordFence.Donotgetmewrong,WordFenceisaverygoodpluginwithamazingfunctionality,justthe2FApartisinconvenient.InWordFence,ifIdonotenterthecodeinthepasswordfield,IwillgetafailedlogineventifIamenteringthecodeinaseparatewindow.TheGoogleAuthenticatorloginwindowsolvesthisproblembyaddingtheGoogleAuthenticatorCodefieldintotheloginpage.Thiscreatesalittleconfusionfornoviceusers,butasmallmessagelabelorcheck-markcaneliminatetheconfusion.
閱讀全部126則使用者評論
參與者及開發者
以下人員參與了開源軟體〈GoogleAuthenticator〉的開發相關工作。
參與者
Ivan
GoogleAuthenticator外掛目前已有14個本地化語言版本。
感謝全部譯者為這個外掛做出的貢獻。
將GoogleAuthenticator外掛本地化為台灣繁體中文版對開發相關資訊感興趣?任何人均可瀏覽程式碼、查看SVN存放庫,或透過RSS訂閱開發記錄。
變更記錄
0.53
AddaPolishtranslation
0.52
AddaDutchtranslation
AddaPortuguesetranslation
0.51
Fixaregressionthatbrokeapppasswords
0.50
Newmaintainerivankk
Conditionallyincludebase32class
0.49
Morestreamlinedsign-upflowforusers,configurationscreenforadmins.
Multisitesupporttoeitherenable2fabyroleonasite,and/oronanetwork.
Addedfiltergoogle_authenticator_needs_setuptodetermineifuserneedstoenable2fa.
Addedtwopartloginprocessthatcanaskfor2facodeonasecondloginscreen.
Fixedasecuritybugthatcontinuedcheck_otpevenifauthenticatehadalreadyreturnedanerror.
0.48
Securityfix/compatabilitywithWordPress4.5
0.47
GooglechartAPIreplacedwithjquery-qrcode
QRcodesnowcontainaheadingsayingWordPress(FeaturerequestbyFlemmingMahler)
Danishtranslation&updated.potfile.
PluginnowlogsloginattemptsrecognizedasMan-in-the-middleattacks.
0.46
Man-in-the-middleattackprotectionadded.
ShowwarningbeforedisplayingtheQRcode.
FAQupdated.
0.45
SpacesinthedescriptionfieldshouldnowworkoniPhones.
Somedepricatedfunctioncallsreplaced.
Codeinputfieldeasiertousefor.jpusersnow.
Sanitizedescriptionfieldinput.
Apppasswordhashfunctionswitchedtoonethatdoesn’thaverainbowtablesavailable.
PHPnoticesoccurringduringapppasswordloginremoved.
0.44
Installation/FAQsectionupdated.
SimplifiedChinesetranslationbyKaijiaFengadded.
Tabindexonloginpageremoved,nolongerneeded,wasusedbyolderWordPressinstallations.
Inputfieldrenamedto“googleotp”.
Defaultdescriptionchangedto“WordPressBlog”toavoidtroubleforiPhoneusers.
CompatibilitywithRyanHellyer’spluginhttp://geek.ryanhellyer.net/products/deactivate-google-authenticator/
Mustenterall6codedigits.
0.43
It’snowpossibleforanadmintohidetheGoogleAuthenticaatorsettingsonaper-userbasis.(Featurerequestby:Skate-O)
0.42
Autocompletedisabledoncodeinputfield.(Featurerequestby:hiphopsmurf)
0.41
ItaliantranslationbyAldoLatinoadded.
0.40
Bugfix,typocorrectedandPHPnoticesremoved.ThankstoDionHulseforhispatch.
0.39
Bugfix,DescriptionwasnotsavedtoWordPressdatabasewhenupdatingprofile.Thankstoxxdesmusfornoticingthis.
0.38
Usabilityfix,inputfieldforcodeschangedfrompasswordtotexttype.
0.37
Thepluginnowsupports“relaxedmode”whenauthenticating.Ifselected,codesfrom4minutesbeforeand4minutesafterwillwork.30secondsbeforeandafterisstillthedefaultsetting.
0.36
Bugfix,nowanApppasswordcanonlybeusedforXMLRPC/APP-Requestlogins.
0.35
InitialWordPressappsupportadded(XMLRPC).
0.30
Codecleanup
Changedgenerationofsecretkey,tonolongerhaverequirementofSHA256ontheserver
Germantranslation
0.20
Initialrelease
中繼資料
最新版本:0.53
最後更新:1年前
啟用安裝數:30,000+
WordPress版本需求:
4.5或更新版本
已測試相容的WordPress版本:5.6.7
語言:
檢視全部15個語言
關閉
Chinese(China)、Czech、Danish、Dutch、English(US)、French(France)、Hebrew、Italian、Norwegian(Bokmål)、Persian、Polish、Romanian、Slovak、Spanish(Spain)、及Swedish.
將這個外掛本地化為你的母語版本
標籤:authenticationloginotppasswordsecurity
進階檢視
評分 檢視全部
5星
99
4星
7
3星
2
2星
1
1星
17
登入以提交評論
參與者
Ivan
技術支援 有話想說?需要協助?
檢視技術支援論壇
關於
官方部落格
主機託管
贊助
技術支援
開發者資訊
參與專案
Learn
展示網站
外掛目錄
佈景主題目錄
WordCamp
WordPress.TV
BuddyPress
bbPress
WordPress.com
Matt
隱私權
PublicCode
@WordPress
WordPress
程式碼,如詩
延伸文章資訊
- 1Google Authenticator 兩步驟驗證設定教學,提昇帳號安全技巧
不過Google 兩步驟驗證已經不需依賴Authenticator ,已經改由Gmail App 方式啟動驗證機制,不過建議還是要到「Google帳戶安全性」頁面開啟。 帳戶安全性 ...
- 2Google Authenticator - Google Play 應用程式
Google Authenticator 會在您的手機上產生兩步驟驗證碼。兩步驟驗證功能會在您登入Google 帳戶時要求以第二個步驟驗證身分,藉此增強您帳戶的安全性。
- 3透過Google Authenticator 取得驗證碼
設定Google Authenticator · 在裝置上前往Google 帳戶。 · 在畫面頂端,輕觸導覽面板中的[安全性]。 · 在「登入Google」底下,輕觸[兩步驟驗證]。 · 在「新...
- 4Google Authenticator – WordPress 外掛
Google Authenticator. 由Ivan Kruchkoff 開發. 這個外掛尚無繁體中文本地化版本。請協助這個外掛完成本地化!
- 5[教學] 開啟Google 兩步驟驗證,使用Google Authenticator 產生 ...
上次在一個公開的場合,向許多朋友介紹Google 服務在數位工作上如何應用,其中我便花了一些時間來宣導安全議題,這對每個人來說其實最重要,卻也常常被輕忽。