canmove, Confirmed users
1,537
edits
m (→Screenshots) |
|||
Line 366: | Line 366: | ||
''The Risk'': Users may accidentally disclose private information that's available on their view of a URL that's not visible to others who access the URL. The data may include anything from their specific session, data typed in after the page was opened, anything created by the content while rendered, anything fetched with asynchronous HTTP requests. This could be as simple as their username typed in the page or as complex as messages and social connections on the site. | ''The Risk'': Users may accidentally disclose private information that's available on their view of a URL that's not visible to others who access the URL. The data may include anything from their specific session, data typed in after the page was opened, anything created by the content while rendered, anything fetched with asynchronous HTTP requests. This could be as simple as their username typed in the page or as complex as messages and social connections on the site. | ||
''Recommendation'': | ''Recommendation'': If the screenshots are high-enough resolution, make it clear that the screenshot being shared reflects the current state of the page (including anything specific to their interactions with the site being shared), and get the user's authorization to share it. | ||
==== Resolution ==== | ==== Resolution ==== | ||
Not Resolved. | |||
= Conformity to Private Browsing Mode (if Applicable) = | = Conformity to Private Browsing Mode (if Applicable) = |