Last modified: 2014-06-27 00:11:08 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T68978, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 66978 - OAuth: Dialog for granting an app permission should clarify or link to what "basic rights" are
OAuth: Dialog for granting an app permission should clarify or link to what "...
Status: NEW
Product: MediaWiki extensions
Classification: Unclassified
OAuth (Other open bugs)
unspecified
All All
: Normal minor (vote)
: ---
Assigned To: Nobody - You can work on this!
: easy
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-06-23 12:12 UTC by Krinkle
Modified: 2014-06-27 00:11 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Krinkle 2014-06-23 12:12:21 UTC
When an application requests the ability to edit on my behalf there is an unordered list with the rights.

But when an app requests basic rights there is only a plain text message saying app "X" requests basic rights. I have no idea what that means. As a developer I'm hoping that means reading. As a user, I'd think "basic" includes editing as well, and I really don't want to grant certain apps that permission (e.g. the kind of tools that abuse OAuth as a way to do OpenID).

Digging back into overview of what these rights mean was hard. After granting access, I found the special page via the Preferences page, then "manage access" which listed "Basic rights" and had a linked list item to https://meta.wikimedia.org/wiki/Special:OAuth/grants#useoauth

That's where I finally found the information.
Comment 1 Chris Steipp 2014-06-23 20:39:37 UTC
We considered linking the individual grants to their Special:OAuth/grants entry, iirc UX didn't think it would be a good idea.

Jared, could you or someone on UX let us know if linking all of those would be problem?
Comment 2 Jared Zimmerman (WMF) 2014-06-23 20:44:56 UTC
The rationale was that this option only shows when no other rights were requested in is only shown when an app wants to use Oauth as a means for account creation. Can someone link to a test app or screen shot of the case where "basic rights" is displayed.
Comment 3 Chris Steipp 2014-06-24 00:26:51 UTC
Jared--https://tools.wmflabs.org/gerrit-patch-uploader/ and click on the "Log in using your mediawiki.org account" link at the top.
Comment 4 Jared Zimmerman (WMF) 2014-06-24 20:02:54 UTC
Thanks Chris, I'd recommend we make "basic access" a link but not style it as such, no color change, no underline until hover. This way we can preserve the simple look for the majority of end users who are likely not to care and should be distracted to go read more about a rather technical issue.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links