Skip to content

What kind of permission screen(s) should the user see? (To avoid spamming and spoofing) #1

Description

@ArthurSonzogni

I understand this is still not fully defined, so it might be hard to give a precise answer.

I would like to know what kind of permission screen the user will have to approve before adding new icons. It seems vital the icon and name are present when the prompt is presented to the user. Otherwise, there are risk of spoofing.

Some question, mostly taken from the security/privacy review preparation:

  1. Do we show a new prompt for every individual icon?
  2. Did you considered throttling requests and then make a "group" prompt?
  3. How would we make the prompt repeatable for every icon, but not spammable?
  4. Does the decision to block an icon remains permanent?
  5. How would users revisit a decision to block an app from adding an additional icon?
  6. Would PWAs know which icons have been blocked by the users so they can stop asking for those icons?
  7. Is there a limit? Can we add 1000 icons in a single request?
  8. Does updating one icon is subject to a "revalidation" via a prompt from the user?
  9. Asking too many things to the user might lead to prompt fatigue. Some might auto-pilot after the 3rd prompt. We are wondering how this could be avoided.

+CC @Sauski, @andypaicu, @amtunlimited, @ArthurSonzogni

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions