Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nextcloud account signup (or later on, Password recovery) should allow for Mastodon account, not requiring an email address #55

Open
esbeeb opened this issue Nov 26, 2023 · 0 comments
Labels
enhancement New feature or request

Comments

@esbeeb
Copy link

esbeeb commented Nov 26, 2023

For new Nextcloud users, I think that having a Mastodon user account be the "back channel" for verifying a user account is better than email. Mastodon accounts can have a mechanism of verifiability (with special "rel=me" set up on a personal website, which Mastodon verifies, and shows green checkmarks in a Mastodon user's profile); email accounts lack this verification mechanism (using one's personal website as a place for verifiability to be cleverly planted).

I think specifying a Mastodon user account should be a "first class citizen" field (in Nextcloud's User management admin page, as in "/settings/users") for any Nextcloud User, such that it can be used for password recovery messages (or any other similar "back channel" notification messages outside Nextcloud). The "Forgot password" feature should be able to make use of this specified Mastodon account - sending a special recovery message as a Mastodon PM ("Private Mention"). Yes, these PM's aren't encrypted, but neither is email (used as a mechanism of password recovery), so it's no worse, that way.

@DaphneMuller DaphneMuller added the enhancement New feature or request label Jan 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants