7 ms·
It's interesting to me that so many people want confirmations. You can remove yourself from any repository you wish at https://github.com/account/repositories
by kneath 15y ago
It's interesting to me that so many people want confirmations. You can remove yourself from any repository you wish at https://github.com/account/repositories https://github.com/account/repositories (yes, I know — this is a confusing place. It's something I'd like to improve). But the idea is that "Confirm? Reject." is the same number of steps/interactions as "Added. Reject." Confirmations wouldn't make the experience any better for someone being annoyingly added to projects. They'd just be rejecting invitations instead of rejecting access.
As it stands, when you are added as a collaborator to a project it shows up in exactly one place — your private, logged in dashboard. It doesn't show up publicly anywhere.
Bypassing confirmations keeps the workflow simple for the professionals who use GitHub and want to collaborate with ease.
- kellishaver 15y agoI tend to agree with this line of thinking. I was added to half a dozen projects today alone. It would have been a pain to have to confirm each one. Your average professional developer isn't trolled on a regular basis, nor would they go about adding "tech stars" to their repos just to have a big name on there or because they wished that person was a contributor - it's unprofessional and rude. So just dismissing yourself from the projects you are maliciously or mistakenly added to seems much simpler than having to confirm each one.
- masterzora 15y agoI agree that I don't want to see confirmations in my GitHub, but you are incorrect about them being equivalent. The optimal way to use confirmations is often not hitting "Reject" to requests you don't want. Just do nothing. In most well-designed systems, as long as there's an outstanding request, they can't bug you any more.
- omaranto 15y agoYou can't have "do nothing" mean both "do not accept (yet?)" and also "accept!"; if no action keeps you from accepting, it means it'll take an extra step to actually accept an invitation. If the common case is not trolling, that adds friction.
- masterzora 15y agoI'm not sure what you're arguing here. Obviously "do nothing" can't mean both. Obviously the entire point of a confirmation would be such that it would take an action to be "accept", so that means that "do nothing" would have to be "do not accept (yet?)". Obviously this is only useful for GH if trolling is the common case. And obviously I started my post by saying I did not want confirmations. So what exactly are you trying to argue against?
- omaranto 15y agoUpon rereading I'm not sure what I meant either. My guess is that I was responding to > The optimal way to use confirmations is often not hitting "Reject" to requests you don't want. Just do nothing. and didn't read carefully. I was probably pointing out that if trolling is not the common case then that system is not in fact optimal (which I think we agree on), without realizing you didn't claim it was the optimal system but only the optimal system-which-uses-confirmations. Sorry about that.
- kstenerud 15y agoI would disagree. If I happened to be in the job market, and my potential employer were to look at my github profile (yes, we do look at your github profile) and find "bigdicksucker" as one of the repos I'm apparently a "contributor" on, well, that wouldn't look too good, would it?
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- Xuzz 15y agoI'd agree, but it's not shown on your public profile, only in your dashboard when you login.
- mojombo 15y agoAs it stands, when you are added as a collaborator to a project it shows up in exactly one place — your private, logged in dashboard. It doesn't show up publicly anywhere. You must make a contribution to a project before you show up in any kind of public fashion.
- jmaygarden 15y agoI got "dong markup" in my RSS reader from pull requests to zedshaw/mongrel2 today. So, the trolling was very much in public view.
- mileszs 15y agoAs Zed mentions in the article, he contributed to the project, which is why it showed up in your RSS feed.
- jmaygarden 15y agoActually, the RSS feed was for zedshaw/mongrel2. It showed up because these trolls were spamming pull requests to a legitimate project.
- ktsmith 15y agoI think the number of steps isn't really that important. For me I care more about permission being explicit and not implicit. I prefer systems where other users have to get my permission to interact with me rather than automatically having permission to do so. It matters more on systems other than github but I think there's still an avenue for abuse with the current set up. It should be fairly trivial to script account creation, project creation, and marking someone as a collaborator. As such a troll could simply automate the process of creating accounts and junk projects and then add the victim as a collaborator to them. The result is a useless dashboard full of crap that the victim has to manually remove themselves from. The troll succeeds in screwing with the victim by wasting lots of time. If permission had to be explicitly granted there would be no change to the dashboard and all of the confirmation messages could be ignored, or ideally bulk deleted from the incoming message queue. I don't have any idea if there's flood prevention mechanisms built into github to prevent this, but with unlimited public projects on the free accounts it seems like an avenue of abuse for trolls.
- kneath 15y agoYou'd just have a dashboard full of invites instead of a dashboard full of add notices. I have a feeling people just recoil to confirmation systems because it's comfortable. But remember that Undo > Confirmation. Always.
- Zev 15y agoGiven the choice between a private dashboard vs a public repo list being spammed, I'll take the former, any day. I don't want either, but the former is an annoyance to me and only me. The latter is something that can (potentially) give a bad impression of me to others. Remember that reputation is important. Always.
- kneath 15y agoI'm not sure how many times I have to say it: Adding someone as a collaborator is not publicly visible until you collaborate (make commits) on the project. At that point we show the activity on your public profile.
- aidenn0 15y agoExcept that when you are added, you start getting e-mail for commits, the subject line of which for dongml was an ASCII art penis. I'm a mongrel2 contributor and I received a half a dozen ascii art penises in my inbox towards the end of last week. Those were easy enough to filter out, since the subject line contains the project, but then the same guy also initiated a couple pull requests against mongrel2 with ascii art penises. This was clearly abusive behavior, and I'm glad that there are now tools to help prevent it.