Element-web: Difficult for new users to find session delete button

Created on 8 Apr 2020  Â·  10Comments  Â·  Source: vector-im/element-web

Description

When managing a user's session list there is no indication of what the checkbox does or how to remove sessions.

Steps to reproduce

  • Open User Settings
  • Go to Security & Privacy section
  • Look at Sessions section
  • Where is the delete button?

2020-04-08 14_29_32-Window

The column containing the checkboxes should have a header to make it clear what the checkbox does and how to delete sessions.

2020-04-08 14_29_32-Window

Version information

  • Platform: Desktop
  • OS: Windows 10
  • Version: 1.5.15
blocked bug design bite-sized usersettings uux

Most helpful comment

Today, I found this post as my riot client was annoying me on a daily basis asking me to review untrusted sessions. Removing outdated sessions did the trick. I was expecting to have the ability to remove these old sessions from the right sidebar as well and not by having to dig into the advanced settings.

This GitHub issue came in handy and was well indexed on search engines hopefully =) Having a "delete" button appearing when we select a session was hard to guess... indeed.

All 10 comments

I think the reason there isn't a header is because that's where the delete button pops up when you select things:
image

Could we move this delete button to a different location, either above or below the list? It's a little clunky in the column and can alter the margins of the page layout when it pops in and out. I think it may look better at the bottom of the list and show a disabled/grayed-out "Delete 0 sessions" when nothing is selected instead of not existing. Then there would be room for the column header (which could also have a counter if wanted)

Sorry for OT but - is it safe to delete sessions? I am asking since I am not sure what happens then with their messages in a room - will they still be there? Will they be still trusted? Does anyone know, please? Cannot find any relevant documentation for it... I want to remove my previous sessions (from my old phone) but not sure whether I can...

Thank you.

is it safe to delete sessions? I am asking since I am not sure what happens then with their messages in a room - will they still be there? Will they be still trusted? Does anyone know, please? Cannot find any relevant documentation for it...

Overall, yes, it's safe and generally good encryption hygiene to delete old sessions. Everyone else in a room has to encrypt their messages for all your sessions, so leaving a bunch of dead ones around causes extra work for others. The new UI coming with cross-signing (will be on release in the next few days) also nudges everyone through toasts to either verify or remove old sessions.

When you remove a session, the messages it sent are still available, but they are marked with a warning shield in the timeline that says "Encrypted by a deleted session".

I'll make a note internally to update our docs with information like this.

In general, please use rooms like #riot-web:matrix.org for questions.

@jryans Thank you very much, much appreciated!

Today, I found this post as my riot client was annoying me on a daily basis asking me to review untrusted sessions. Removing outdated sessions did the trick. I was expecting to have the ability to remove these old sessions from the right sidebar as well and not by having to dig into the advanced settings.

This GitHub issue came in handy and was well indexed on search engines hopefully =) Having a "delete" button appearing when we select a session was hard to guess... indeed.

So, what went wrong if there's a list of unverified sessions but no checkboxes at all, so no chance to delete them?

That you're probably not looking in Settings > Security & Privacy.

That you're probably not looking in Settings > Security & Privacy.

Correctly, I was looking at the profile which has the same list and the verify options but no hint on how to remove the sessions. So, thanks for your hint :)

I was expecting to have the ability to remove these old sessions from the right sidebar as well and not by having to dig into the advanced settings.

This is the subject of #13187 I think.

I expect a lot the feedback here would be addressed by the refreshed devices / sessions settings UI in https://github.com/vector-im/riot-web/issues/11221.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

richvdh picture richvdh  Â·  3Comments

t3chguy picture t3chguy  Â·  3Comments

arthurlutz picture arthurlutz  Â·  3Comments

richvdh picture richvdh  Â·  3Comments

nvbln picture nvbln  Â·  3Comments