element-hq / element-hq/element-meta

UX for "Undo Verification" (CRUD/Management of Verified Sessions)

Open
#2,298 0 comments 0 reactions 0 assignees View on GitHub
T-Defect
Dominant language
No language data
Stars
112
Forks
25
Avg merge
6h 6m
Merged PRs (30d)
4

Description

### Steps to reproduce

1. Click on an unverified session of another user
2. Choose to verify by text
3. Accidentally click "verify" when you just want to close the window
4. ...
5. Burn everything. Create a new account because now you've trusted something that's untrusted, and you can't mark it as untrusted??

### Outcome

#### What did you expect?

I should be able to manage other user's trust. If I trusted something in the past, I should be able to see that and change it to "untrusted"

#### What happened instead?

I accidentally marked one contact's untrusted devices as trusted, and now *nothing* is trustworthy >:0

### Operating system

Debian Linux

### Application version

Element version: 1.11.57 Crypto version: Olm 3.2.15

### How did you install the app?

apt

### Homeserver

nitro.chat

### Will you send logs?

No

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the verification flow described in the reproduction steps and the surrounding session-trust UX in the Element client. Done means a user can inspect and change another user's verified session back to untrusted, and closing the dialog cannot accidentally confirm verification.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.