3 ms·
My point was that no, of course the feature doesn't require it, but their particular implementation of the feature does. For example, maybe they implemented per
by dual_basis 7y ago
My point was that no, of course the feature doesn't require it, but their particular implementation of the feature does. For example, maybe they implemented per-user sharing first, which obviously would need to know who is accessing the document. Then they realized there are some use cases for sharing the document publically, but they basically just treated this (internally, i.e. according to their implementation) as a wildcard in the authentication portion. That is to say, the public sharing works exactly the same as the per-user sharing, but with a * in the "allowed users" field.
Clearly it doesn't have to and should not be this way. My point was that:
1. They are saying that their particular implementation did require it to be this way.
2. Almost every web app could be made to require less private data from the user, however if this is something that GDPR is going to enforce then there will end up being some subjective analysis (according to non-tech lawyers?) as to whether a particular implementation was in violation.