Appearing to log in with someone else's pubkey #372

Closed
opened 2023-02-28 03:47:13 +00:00 by JimSB · 0 comments
JimSB commented 2023-02-28 03:47:13 +00:00 (Migrated from github.com)

Describe the bug

Logging in with someone else's pubkey looks like you sign in as them. You see their settings page, you can also see a list of their DMs, they display <ERROR> but it exposes who you have been communicating with.

I believe this is confusing for someone first navigating to Nostr, because before logging in there's no search icon either, so they may be arriving with just someone else's pubkey on their clipboard, then as an example they can see someone else's settings all of a sudden with a different avatar and banner, but might be unsure they must now logout and use their own private key, and of course can't actually edit anything yet

(someone else's DM list)
image
image

To Reproduce

Steps to reproduce the behavior:

Paste someone else's pubkey to login

Expected behavior

Perhaps there should be a disclaimer when entering pubkey or logic to avoid exposing the DMs list etc. - not sure if this is a broader issue with Nostr clients and can be remedied easily? Changing this user flow I believe will help onboard new people.

Desktop (please complete the following information):

  • Chrome, Brave, and Firefox

Smartphone (please complete the following information):

  • iOS
**Describe the bug** Logging in with someone else's pubkey looks like you sign in as them. You see their settings page, you can also see a list of their DMs, they display `<ERROR>` but it exposes who you have been communicating with. I believe this is confusing for someone first navigating to Nostr, because before logging in there's no search icon either, so they may be arriving with just someone else's pubkey on their clipboard, then as an example they can see someone else's settings all of a sudden with a different avatar and banner, but might be unsure they must now logout and use their own private key, and of course can't actually edit anything yet (someone else's DM list) ![image](https://user-images.githubusercontent.com/8608634/221747766-d2ad2650-5354-48bd-9735-4a9e25c0d071.png) ![image](https://user-images.githubusercontent.com/8608634/221748242-24508a30-d20b-4b98-aede-81dfaef37594.png) **To Reproduce** Steps to reproduce the behavior: Paste someone else's pubkey to login **Expected behavior** Perhaps there should be a disclaimer when entering pubkey or logic to avoid exposing the DMs list etc. - not sure if this is a broader issue with Nostr clients and can be remedied easily? Changing this user flow I believe will help onboard new people. **Desktop (please complete the following information):** - Chrome, Brave, and Firefox **Smartphone (please complete the following information):** - iOS
Sign in to join this conversation.
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: Kieran/snort#372
No description provided.