Page MenuHomePhabricator

Replace link to WMF privacy policy with link to app's privacy policy on OAuth authorize dialog
Open, HighPublic

Description

OAuth apps have their own rules for handling private data, which are different from the WMF privacy rules. Users should be using such apps at their own risk, but to be able to evaluate such risk, there should be some way to evaluate the app's privacy policy & data retention rules.

We should add a new field (oarc_privacy_policy_url or similar) to the consumer table, ask the owner for a privacy policy URL when registering the app, and display that URL in the authorization form.

Details

Reference
bz62686

Event Timeline

bzimport raised the priority of this task from to High.Nov 22 2014, 2:53 AM
bzimport set Reference to bz62686.
bzimport added a subscriber: Unknown Object (MLST).
Tgr renamed this task from Remove link to WMF privacy policy on OAuth Authorize to Replace link to WMF privacy policy with link to app's privacy policy on OAuth authorize dialog.May 12 2015, 10:22 AM
Tgr updated the task description. (Show Details)
Tgr set Security to None.
Aklapper added a subscriber: dpatrick.

The link is to [[Project:Privacy policy]] on the local wiki by default. Can this task be resolved?

The link is to [[Project:Privacy policy]] on the local wiki by default. Can this task be resolved?

The task is about managing per-app privacy policies. I tried to clarify the task description.