Skip to content

When v2.22.0 is sufficiently rolled, out, make rules for verification stricter #7340

@Hocuri

Description

@Hocuri

When most people have v2.22.0 (i.e. around December/January), we want to have stricter rules for who counts as verified:

  • Revert feat: Be more generous with marking contacts as verified for now #7336
    • Unresolved question: Do we also want to reset direct verifications, or only indirect verifications?
      • Direct verifications are generally not as broken as indirect verifications
      • If we reset all direct verifications, maybe some people will complain
      • But, verifications now have a stronger meaning, because verifications expire.
  • Revert feat(backwards-compat): For now, send Chat-Verified header (instead of _verified) again #7349 (commit 8b4c718)
  • Possibly: Don't verify people who joined a group (on Alice's side), for two reasons:
    • People often create a link and paste it into a chat for others to join
    • Even if the group creator has others scan a QR code, they often won't remember who was who
      This can be easily implemented by creating AUTH tokens for group-invite-codes as immediately expired.
      If we don't reset all verifications now, then this can be done in a few months rather than now.
      OTOH, it's nice to have an "along-the-way" verification.
  • Possibly: Don't verify the inviter when joining a group (on Bob's side)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions