MetaMask / MetaMask/metamask-extension

Why initiate connection on User Action and Never on page load?

Open
#11,448 0 comments 0 reactions 0 assignees View on GitHub
area-api area-documentation
Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

I'm sorry if this might not qualify as a "Bug", but the documentation does not make this clear, nor could I find any resources pointing to an explanation of why MetaMask strenuously advises only "Connecting" on "User Action such as a button click", and **never** on page load? I assume this has to do with security, however I fail to see why this is critical IF the user is prompted to confirm their connection anyway, and arguably the "user action / intent" is opening your Dapp in the first place... Please help me understand the reasoning here, because the Documentation does not

Contributor guide

Open the contributing guide

Research direction

No file, test, or documentation entry point is named. Start by locating the MetaMask documentation covering connection requests and user-initiated actions, then research the security rationale and determine where that explanation belongs. Done means the documentation clearly explains why connection should not begin on page load and addresses the confirmation prompt concern.

Written by the indexing model from the issue text.

Assessment

Domain
blockchain, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.