Skip to content

Disable invites for 1:1 private DMs/direct chats by default OR ask for 2nd user's consent before actually inviting #831

@opusforlife2

Description

@opusforlife2

Suggestion

Please read element-hq/element-meta#320 for context.

I would like for all clients/servers to disallow inviting a 3rd user into a private 1:1 chat by default.

If a user wants advanced functionality by inviting bots or personal assistants, that should involve an extra step or two, not the other way around, as the workaround suggested in the linked issue does.

The most straightforward method of creating and using a 1:1 chat, without tweaking anything, should cater to the average non-tech-savvy user, someone who would have no idea of the consequences of being part of a 1:1 chat where both users are admins and can invite all and sundry to become part of a potentially private conversation.

This could be a very targeted, narrow component of #289.

Alternative

I would like for all clients/servers to ask the 2nd user for consent before sending out an invite to any 3rd user to a private 1:1 chat. This will ensure that no single user can abuse their admin privilege to allow others to gatecrash a private conversation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementA suggestion for a relatively simple improvement to the protocol

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions