umputun/remark42

UI changes for GDPR

Open

#54 opened on May 26, 2018

View on GitHub
 (0 comments) (3 reactions) (0 assignees)Go (432 forks)user submission
discussionenhancementfrontendhelp wanted

Repository metrics

Stars
 (5,500 stars)
PR merge metrics
 (Avg merge 87d 10h) (18 merged PRs in 30d)

Description

related to #47

I think we should add a popup/dialog after the user clicks on github/fb/goolge login links. This popup will ask for confirmation and will inform about cookies and will explain what info will be sent for such login.

Probably we should say:

 This service uses cookies.

 We use authentication cookies to identify the user once he has logged in. 
 
<show/hide detail>
|cookie name | description | duration| technical details|
|JWT | Signed web token identifying user| 1year| see https://tools.ietf.org/html/rfc7519|
|XSRF_TOKEN|Random ID preventing Cross-Site Request Forgery| 1year| see https://en.wikipedia.org/wiki/Cross-site_request_forgery|  

TBD: some text explaining what we send to oauth2 provider and what info we get back

if anyone has a good example what this dialog should be, pls share.

Contributor guide