element-hq / element-hq/element-meta

Verification dance is too brittle

Open
#2,137 0 comments 1 reaction 0 assignees View on GitHub
A-E2EE-Cross-Signing T-Enhancement
Dominant language
No language data
Stars
112
Forks
25
Avg merge
6h 6m
Merged PRs (30d)
4

Description

### Steps to reproduce

After a failed attempt at verifying the device, Element X doesn't attempt to verify again, leaving the user with empty rooms that don't have (encrypted) conversation history.

Tapping the blue message "conversation history is not available" or pulling down the conversation list to refresh does nothing, with users expecting to be able to trigger the verification dance again.

1. Install Element X on Android, login
2. Accept verification prompt to verify session, in order to access encrypted conversation history:
3. Switch to Element Android, go through the verification steps using emoji verification
4. Switch back and forth between Element X and Element to complete the verification, probably miss a step (like letting the process time out)

### Outcome

#### What did you expect?
Element X should prompt to verify regularly and not only attempt once. Users will miss a step, life will get in the way, things will time out. Element X should help its users through these events.

#### What happened instead?
After a failed verification attempt, Element X seems happy to just tell you your conversation history is not available.

Admitting conversation history is not available should be the lowest level of what's acceptable for the app to tell you. It should try to fix that situation several times before leaving the user with a chat history in a broken state.

### Your phone model

Pixel 5

### Operating system version

CalyxOS 4.13.3-2 (Android 13)

### Application version and app store

v0.2.3 Google Play, via Aurora Store

### Homeserver

matrix.org

### Will you send logs?

Yes

### Are you willing to provide a PR?

No

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the failed device-verification flow on Android using the listed Element X and Element versions, including a timed-out step. Trace what happens when the verification fails and when the conversation-history message or conversation-list refresh is used; done means users can retry verification and regain encrypted conversation history after a failed attempt.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
authentication, mobile-dev
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.