While this will work a very large proportion of the time, and has a big benefit of offloading security as you mention, email is fundamentally asynchronous and can be affected by issues outside of your (and the email providers') control.
Another point that UX designers might make is that this solution necessarily takes users away from your site to complete login, and that can introduce a place for users to drop off. I'm not sure it's that significant, but I've heard it used as an argument.
> Here are the screenshots of working example on an iTerm2 terminal (Mac OS), oh-my-zsh with powerlevel9k theme and powerline nerd-font + awesome-config font with the Solarized Dark color theme.
> The article starts by complaining about "drive-by issue comments", then described opening what might be considered a drive-by issue. That could be construed as contradictory.
The article is reasonably clear that "drive-by issues" are ones where people leave comments uninvited, and it's also explicit that Caroline was specifically asked to review the survey in question. So it's hard to read that as contradictory.
I'm not certain, but I believe the subtle point parent was trying to make, is the difference between "base 10" and "base ten". Every base is "base 10" in its own base ;)
Maybe because the app could be a mail client? If I downloaded a mail client and it wasn't able to delete my email I'd think it was a pretty crap piece of software. The same as I'd expect if I wanted a fully featured mail client to connect via IMAP.
I'd also feel a bit annoyed if a Twitter client I was using was unable to delete tweets, and I had to go back to the Twitter website to do that.
The thing about making APIs to let other people interface with your product is that you have to expose all the functionality of that product, or there's not really any point.
There are some fair comments in this thread saying that the "manage" permission is significant enough that it should be flagged a bit (or a lot) more strongly than the common "identify" permission, but personally I don't think the point of the API is something that needs questioning.
Well, apart from "6) Don’t use only the “latest” tag".
If I'm not using latest, and I don't know that the Apache and Nginx images have been updated, then it's very likely that "yum update" might do something.
Your point about whether doping is inherent in cycling is a good discussion point, but the research that the article describes shows how "Winners turn to cheating" even in cases where drugs aren't part of the equation.
The parent wasn't talking about the individual validation of email addresses (although I guess that may be a part of the answer), but instead about checking the presence of a recipient, subject, sender etc as part of static typing.
I can see where that comes from, the functionality of Youtube is nothing without its videos.
But on the other hand, Youtube wouldn't have as many videos – specifically the content creators wouldn't have as much of an incentive to upload them – without the social features being there.
Another point that UX designers might make is that this solution necessarily takes users away from your site to complete login, and that can introduce a place for users to drop off. I'm not sure it's that significant, but I've heard it used as an argument.