Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Revoked oAuth token #10190

Closed
charliescheer opened this issue Sep 21, 2018 · 1 comment
Closed

Revoked oAuth token #10190

charliescheer opened this issue Sep 21, 2018 · 1 comment

Comments

@charliescheer
Copy link
Contributor

This problem came up a little bit ago and I didn't have time to write it up, so it is not as pressing as it was... but it could come up again... So a few months ago for security reasons we revoked a large number of WordPress.com passwords, requiring the users to reset their password before they would be able to access their site or account.

With users who did not see our email about needing to reset their password, if they were logged into the app before the password reset, they would still be able to explore the WordPress app, but if they tried to do anything that would require authentication, like posting or uploading images, they would see a generic error, with no indication that the problem was their password having been invalidated. This created a lot of confusion amongst users who seemingly were connected to the app, but were suddenly unable to interact with their site. A similar problem would occur if a user goes to their account in a web browser, resets their password, and then doesn't re log back into the app.

Would it be possible to detect that the passwords had been revoked or changed? If so, can we display to the users a more detailed error then the generic error that is appearing currently?

@rachelmcr
Copy link
Member

Thanks for the report and description! We have an open issue about this here: #9392

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants