canmove, Confirmed users
1,537
edits
| Line 394: | Line 394: | ||
F1 doesn't intentionally retain data. | F1 doesn't intentionally retain data. | ||
'' | ''Requirements'': Make it clear when enabling the feature that you will be authorizing Mozilla to access accounts on your behalf. | ||
'''Principle: Sensible Defaults''': | '''Principle: Sensible Defaults''': | ||
| Line 404: | Line 404: | ||
F1 doesn't retain much data at all on the servers. As designed, the Sharing Service has complete OAuth-based access to all your accounts. | F1 doesn't retain much data at all on the servers. As designed, the Sharing Service has complete OAuth-based access to all your accounts. | ||
'' | ''Requirements'': Brainstorm alternative directions and ways to avoid obtaining OAuth tokens to perform sharing; ideally, authentication/sharing could be performed without our servers as a proxy, minimizing risk. | ||
==== Resolutions ==== | ==== Resolutions ==== | ||
{{risk|Not Resolved}} | |||
= Follow-up Tasks and tracking = | = Follow-up Tasks and tracking = | ||