Dangerous OAuth scopes #3051
HellishBro
started this conversation in
Ideas
Replies: 3 comments 4 replies
|
This has good uses yes but due to the sheer amount of people who use it for bad. I honestly dont think it should be given a chance., Im also like 99% sure fluxer doesn't even support apps, And the send message as you just feels wayy to dangerous and i feel it should never be added. but it could help for things like plural bots |
1 reply
|
As long as even the users who like to just click buttons without giving anything a thought are made aware of that these perms are being activated on their account i guess... |
2 replies
|
I think "send messages as you" is problematic to add, even if there is a warning and the sudo mode requirement, because you don't know whether someone actually said something or if it was a bot doing that through the OAuth scope |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Current problem
Discord has an OAuth scope called "join servers for you", and it allows apps to join servers for you. While this is a scam hazard, it is also an important scope and not all uses of it are malicious.
Discord also doesn't really do a good job of communicating that this scope may be dangerous.
Proposed change
I propose that Fluxer add "dangerous scopes", AKA, scopes that require an elevated permission level "sudo mode" to authorize. This will be the same pop-up modal as changing password or deleting account.
Then, alongside this, Fluxer could add a "join communities for you" scope that apps could use.
Additional information
Fluxer could also add a "send message as you" scope too. Risk of scammy / spammy, but there could be benevolent use cases, and furthermore, the sudo mode should discourage most scammers or malicious actors.
Acknowledgements
All reactions