The email address field of an OAuth application cannot be left empty, cannot differ from the user's verified email address, and is publicly visible, even for owner-only consumers. Not all bot owners might want to publish their wiki email address.
Description
Description
Details
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Open | None | T142282 Improve consumer registration experience for bot owners (owner-only consumers) | |||
Resolved | Tgr | T142275 Owner-only consumers should not expose the user's email address |
Event Timeline
Comment Actions
Change 316302 had a related patch set uploaded (by Gergő Tisza):
[WIP] Add development stage, refactor approval workflow
Comment Actions
Change 996975 had a related patch set uploaded (by Gergő Tisza; author: Gergő Tisza):
[mediawiki/extensions/OAuth@master] AccessControl: Hide email and security restrictions
Comment Actions
Change 996975 merged by jenkins-bot:
[mediawiki/extensions/OAuth@master] AccessControl: Hide email and security restrictions