cubing / CubePB

⏱ A website for storing and showcasing your personal bests in cubing-related events.
https://cubepb.com
GNU General Public License v3.0
13 stars 0 forks source link

Overly broad WCA OAuth scope? #3

Closed jfly closed 3 years ago

jfly commented 3 years ago

There's an oauth url with a scope defined in a few places in this repo:

All of those have scope=public+dob+email+manage_competitions. Do you really need dob and manage_competitions? If you do, it would be nice to have an explanation of why when I log in.

Neat project, btw! I look forward to learning more about it =)

big213 commented 3 years ago

Fair point, and thanks for bringing this to my attention. I guess the dob and manage_competitions scopes are not really needed, I think they were added because I just copy and pasted that part from some other project that did use them. Anyway, I will get these references removed in the next release.