# Invitations, implicit account creation, self-deleting and usernames

**URL:** https://meta.discourse.org/t/invitations-implicit-account-creation-self-deleting-and-usernames/55252
**Category:** Feature
**Created:** [Janeiro 6, 2017, 12:36am UTC](https://meta.discourse.org/t/invitations-implicit-account-creation-self-deleting-and-usernames/55252 "2017-01-06T00:36:35Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![claas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/claas/32/71725_2.png) [@claas](https://meta.discourse.org/u/claas)
#### Post date: [Janeiro 6, 2017, 12:36am UTC](https://meta.discourse.org/t/invitations-implicit-account-creation-self-deleting-and-usernames/55252/1 "2017-01-06T00:36:35Z")

</div>

So **the invitation feature** allows registered users to invite people to the community.

This works as follows:

1. A registered user goes to its profile \> “Invites” \> “+ Send an Invite” and provides the email address of person to be invited:  

2. The user can _Send Invite_ directly via Discourse and/or _Copy Invite Link_ and send the link via another channel.

3. If the user chooses to _Send Invite_, the mail will say (unless customized):

4. Once the invited user opens the link (whether via this invite mail or not), **Discourse will automatically create an account** (given that the inviting user is a trusted user).

The rationale for this is that this allows the invited user to get started and post right away. If the invited user had to provide any details, this would reduce usability and likely also the probability of an invited user to _actually_ dive into the conversation and join the community.

**However** , there are **three challenges** :

1. _The implicit account creation might be surprising_ …  
a) … for the inviting user, as this is what’s meant by “no login required”,  
b) … for the invited user, if she/he didn’t read the invite mail beyond the link _or_ only received the invite link via a different channel.
2. _The invited user may decide not to join the community, but –without intending so– leave its account intact_, …  
a) … if the user did not realize that an account was created (and ignores the “Set password for your Community account” mail),  
b) … if the user does not expect there to be a “Delete my account” function _or_ simply doesn’t find it.
3. _The username(\*) of the implicitly created account is derived from the email address and the user is never prompted to explicitly revise this choice, which means that …_  
a) … the username may contain information that the user may not intend to share with the public or other users of the community (like full name or _ilovebritneyspears87_) and which may allow deducing the user’s mail address (a good guess would be [username@gmail.com](mailto:username@gmail.com)),  
b) … the username may be unhandy for mentioning.

(\*) = and the _name_, as it appears

So **you may not agree** with some of these points, **but what if** we could solve these challenges without hurting anybody and without breaking the premise that invited users could get started and post right away?

**We could** …

1. … be more explicit about the account creation …  
a) … in the _Send an Invite_ dialog,  
b) … be more explicit in the invite mail (e.g. by mentioning it before the link),  
c) … be more explicit in a sticky “notification” similar to what the blue “you’re in Bootstrap mode”.
2. … differentiate between the link in the invite mail and the link from the “Copy Invite Link” and prompt the user for confirmation only when opening the link from the “Copy Invite Link”.
3. … defer the account creation until the first action (e.g. writing a reply or liking a post).
4. … prompt the user to revise its username at some point (e.g. before its first public action).
5. … make the “Delete my account” option more visible (e.g. further at the top of the profile/settings) and possibly explain, until when or under what circumstances this will still be possible (or not) “in the future”.
6. … be more explicit about the option to delete the account (and possibly inform about this after a couple of days, if the user has not had any activity).
7. … delete the account automatically, if there was no activity (and if we properly announce this to the user before).

So **what do _you_ think?**

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [Janeiro 6, 2017, 12:38am UTC](https://meta.discourse.org/t/invitations-implicit-account-creation-self-deleting-and-usernames/55252/2 "2017-01-06T00:38:08Z")

</div>

I really don’t think a poll is a good idea for this.

---

<div class="post-metadata">

### Author: ![claas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/claas/32/71725_2.png) [@claas](https://meta.discourse.org/u/claas)
#### Post date: [Janeiro 6, 2017, 12:41am UTC](https://meta.discourse.org/t/invitations-implicit-account-creation-self-deleting-and-usernames/55252/3 "2017-01-06T00:41:25Z")

</div>

So be it. Switched back to list. 👼

PS: Can you read my mind?

[https://github.com/discourse/discourse/commit/8a5dad16bd273255517cc722f42ae9238769f1c9](https://github.com/discourse/discourse/commit/8a5dad16bd273255517cc722f42ae9238769f1c9)

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [Janeiro 6, 2017, 12:46am UTC](https://meta.discourse.org/t/invitations-implicit-account-creation-self-deleting-and-usernames/55252/4 "2017-01-06T00:46:38Z")

</div>

> [@claas](#):
>
> prompt the user to revise its username at some point (e.g. before its first public action).

This already happens in the welcome PM, with a link to the preferences page:

 ![](https://global.discourse-cdn.com/meta/original/3X/e/b/eb6d71d841d37af5f13566aa4fb1010d51c74a2e.png)

---

<div class="post-metadata">

### Author: ![claas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/claas/32/71725_2.png) [@claas](https://meta.discourse.org/u/claas)
#### Post date: [Janeiro 6, 2017, 1:00am UTC](https://meta.discourse.org/t/invitations-implicit-account-creation-self-deleting-and-usernames/55252/5 "2017-01-06T01:00:21Z")

</div>

> [@codinghorror](#):
>
> This already happens in the welcome PM, with a link to the preferences page:

I was aware of this. What I had in mind with “prompt the user” was more "_prompt the user with a choice between “Yes, keep **wumpus1\_test** as username” or “No, change username to |\_\_\_\_\_\_\_\_|”_. In doubt, it only costs the user a click, but gives us the guarantee that this username is complying with the user’s intention. Here in Germany, users tend to appreciate –and demand– explicitness, I think.
