Page MenuHomePhabricator

On the "Watchlist" preferences panel, don't show the user's watchlist token; instead just link to Special:ResetTokens
Closed, ResolvedPublic

Description

We should treat it the way users expect "secret" information like this to be shown – hashed out until a user interacts with it (at least in JS mode; probably not worth it for PHP).

Event Timeline

For historical context, this preference used to be an editable text field a long time ago, but then we realized people don't understand it, so that was removed and replaced with Special:ResetTokens, but the preference help text remained on Special:Preferences.

I'm not sure if there is a reason to display it at all? We could just replace it with a link/button to Special:ResetTokens, like we do e.g. for the password.

I suppose it's there for people to copy-paste into third party tools like AWB? Though it's available on Special:ResetTokens, the interface isn't lovely. Maybe we should just make that interface better though, yeah, let's do that.

Jdforrester-WMF renamed this task from On the "Watchlist" preferences panel, don't show the user's watchlist token without some interactivity first (in JS mode) to On the "Watchlist" preferences panel, don't show the user's watchlist token; instead just link to Special:ResetTokens.Nov 20 2017, 11:16 PM

Change 392539 had a related patch set uploaded (by Jforrester; owner: Jforrester):
[mediawiki/core@master] Preferences: Don't show the watchlist token; just link to ResetTokens

https://gerrit.wikimedia.org/r/392539

Hmm, I didn't think it could be useful to any third-party tools, since this only gives access to reading the watchlist. If there are actually any, then we can just leave this alone.

Slightly related (I didn't test whether the above patch also fixes this, but it doesn't seem unlikely, so I'll comment here instead of a new task): Currently the info text about the token is duplicated, once below (directly visible) and once behind the help icon:


(To all hackers reading this: No, this is no longer my watchlist token, apart from the fact that my watchlist on beta.wmflabs doesn't contain anything interesting).

Slightly related (I didn't test whether the above patch also fixes this, but it doesn't seem unlikely, so I'll comment here instead of a new task)

Yeah, I fixed that whilst I was at it.

Change 392539 merged by jenkins-bot:
[mediawiki/core@master] Preferences: Don't show the watchlist token; just link to ResetTokens

https://gerrit.wikimedia.org/r/392539

Jdforrester-WMF closed this task as Resolved.Nov 22 2017, 9:03 PM
Jdforrester-WMF claimed this task.
Jdforrester-WMF removed a project: Patch-For-Review.