UI to invite users to groups can mislead users to add the wrong users

RESOLVED INACTIVE

Status

RESOLVED INACTIVE
a year ago
6 months ago

People

(Reporter: kang, Assigned: tasos)

Tracking

Details

(URL)

When adding/inviting a user to a group the UI only let you see the User's full name.
Full names are not unique, and it is not possible to add a user with 100% assurance that you're adding the correct user (in particular when several users have the same full name).
You have to first add/invite them, then load the group members, click on their name and verify it's the correct user (and if not remove them from the group).

Not ideal/may lead to security troubles.

I would propose to do something such as using the user login/email or at least displaying it in the results when you look for the person to add. Megan (mbranson) may have better suggestions though

Reproduction:
URL where this happens (for example):
https://mozillians.org/en-US/group/cis_whitelist/edit/#invitations (field: "invites")
Adding Tasos in copy.
(Assignee)

Updated

a year ago
Assignee: nobody → tasos
Status: NEW → ASSIGNED
One "hack" I use frequently is to search a user with their slug (hmitsch in my case). This returns exactly the user one is looking for. Not good UX but does the job.

kang, if this works for you, I'd suggest to close this issue as we need and will improve group management UX during the Mozillians Repositioning journey.
Flags: needinfo?(gdestuynder)
ive also opened this in github and kind of consider it a possible security issue. its long standing, but also since its in github we can close this one regardless
Status: ASSIGNED → RESOLVED
Last Resolved: 6 months ago
Flags: needinfo?(gdestuynder)
Resolution: --- → INACTIVE
You need to log in before you can comment on or make changes to this bug.