Update wording and help text for private pages using shared password
lb- opened this issue · comments
Is your proposal related to a problem?
Wagtail's page privacy feature could be improved to communicate better to the user that the password created is different from using authentication (log in) to restrict access.
This issue is one part of a wider plan to improve this feature - see #10588
Describe the solution you'd like
For private access dialogs (collection and page privacy), the following should be changed;
- Update the ordering of the private access so that it goes from most public to most secure.
- The current ordering with the 'shared password' between the two logged in options does not make it easy to communicate the differences.
- Change the wording for the labels:
- "Private, accessible with the following password" -> "Private, accessible with a shared password"
- "Private, accessible to logged-in users" -> "Private, accessible to any logged-in users"
- Update the field label from "Password" to "Shared password"
- Add help text (use our shared field template includes for this) with help text as follows:
- "Shared passwords should not be used to protect sensitive content, anyone who has this password will be able to view the content."
- Ensure all other references for private pages/collections are updated with references to 'password' becoming 'shared password'. Such as;
- Documentation - https://docs.wagtail.org/en/stable/advanced_topics/privacy.html & https://docs.wagtail.org/en/stable/topics/permissions.html#image-document-permissions
- Audit logging
- Selected state in the side panel or the collection edit page
- Once merged - a new issue on the Wagtail Guide will be needed to ensure screenshots get updated https://guide.wagtail.org/en-latest/how-to-guides/manage-collections/#privacy-settings
Screenshots of current state
Audit logging
Describe alternatives you've considered
There were various discussions on #10588 about other approaches, the core team have agreed that this is a good first step.
Additional context
- Some of this (help text) was done in #10729 - but do not use this PR, instead create a new one.
- Documentation - https://docs.wagtail.org/en/stable/advanced_topics/privacy.html & https://docs.wagtail.org/en/stable/topics/permissions.html#image-document-permissions
Out of scope
Updating the default password template form does not need to be changed. Many sites will customise this.
Working on this
- Anyone can contribute to this who is willing to take the time to understand how the private access features work and review the changes suggested above and work through the code to find out where to update this.
- Unit tests and documentation must be updated with any PR
- View our contributing guidelines, add a comment to the issue once you’re ready to start.
I would like to work on this!
Go for it @rohitsrma
@rohitsrma are you able to create an issue with a new screenshot or two on the Wagtail guide repo.
Advise that the screenshots and description within this page - https://guide.wagtail.org/en-latest/how-to-guides/manage-collections/#privacy-settings - will need to be updated for 6.2.
Include a link to this issue and your PR. Thanks again for helping to improve Wagtail.
Thanks @lb- I've created an issue wagtail/guide#390.
Legend! Thanks.