GitLab should identify the new OAuth Application that has been authorized as part of the notification message
Today I received an email notification to tell me that a new OAuth application had been authorized.
This email notification only led to more questions than it answered.
- Which GitLab account is this for? I have multiple accounts, including Administrator accounts. The email doesn't tell me which one it is. If it is the administrator account, this is something I would need to treat as an immediate major security breach.
- Which application is it for? There is no indication of this either.
- Knowing which permissions the account has would help too.
I was especially alarmed, since I had not added any OAuth Applications today (or recently). Did this mean that my account had been compromised? This would be especially serious for my Administrator account.
It turns out that the "OAuth Application" was GitLab Pages, although I'm not sure why this issued this notification at this point in time, since I've been using GitLab Pages for multiple years.
As the notification was issued, it lead to some consternation on my behalf: having more details in the notification would help with this.
Related to !129928 (merged) and #414375 (closed)
