Issue 516 in rietveld: upload.py

3 views
Skip to first unread message

riet...@googlecode.com

unread,
Jan 25, 2015, 8:16:38 PM1/25/15
to coderev...@googlegroups.com
Status: New
Owner: ----
Labels: Type-Defect Priority-Medium

New issue 516 by ben.darn...@gmail.com: upload.py
https://code.google.com/p/rietveld/issues/detail?id=516

What steps will reproduce the problem?
1. Enable two-factor auth on a gmail account
2. Run upload.py
3. Enter this gmail account and a password (not an "app-specific password")

What is the expected output? What do you see instead?

It suggests "use an app-specific password instead". I would prefer it to
recommend --oauth2.


What browser are you using? What version? On what operating system?

Browser n/a; OSX 10.10


At what URL are you accessing Rietveld? codereview.appspot.com


Please provide any additional information below.

"App-specific passwords" are inconvenient and a security risk (they allow
full access to the account; they are not actually constrained to a
particular app). It would be better in most cases to recommend re-running
with the --oauth2 flag instead of suggesting an app-specific password. (I
would also support making --oauth2 the default, but that's a more
contentious change than updating the error message).

--
You received this message because this project is configured to send all
issue notifications to this address.
You may adjust your notification preferences at:
https://code.google.com/hosting/settings
Reply all
Reply to author
Forward
0 new messages