Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Kinda broken. #1

Open
Semisol opened this issue Nov 24, 2020 · 7 comments
Open

Kinda broken. #1

Semisol opened this issue Nov 24, 2020 · 7 comments

Comments

@Semisol
Copy link

Semisol commented Nov 24, 2020

I think this is kinda very flawed.
First, you can do this:

  1. Login to site A
  2. Site A gets code from site B
  3. User posts code
  4. Site A now has control over the account on site B
@Semisol
Copy link
Author

Semisol commented Nov 24, 2020

Also quick reminder that it will be dropped after 1-2 months of ScratchOAuth2's release.

@aetinx
Copy link

aetinx commented Nov 24, 2020

Also quick reminder that it will be dropped after 1-2 months of ScratchOAuth2's release.

What is ScratchOAuth2?

@Semisol
Copy link
Author

Semisol commented Nov 25, 2020

Also quick reminder that it will be dropped after 1-2 months of ScratchOAuth2's release.

What is ScratchOAuth2?

New system without the flaws.

Images
We are working on how it works right now.

@Semisol
Copy link
Author

Semisol commented Nov 25, 2020

It fixes a problem where:
Site A wants you to post a code to your profile, obtained from Site B
You do it, and site A is now logged in as you in site B

@Semisol
Copy link
Author

Semisol commented Apr 3, 2021

Any fixes?

@micahlt
Copy link
Owner

micahlt commented Apr 3, 2021

I never really got the point of this issue - I'm confused by "Site A" and "Site B". Use Modchat for example and explain it again if you can.

@Semisol
Copy link
Author

Semisol commented Apr 4, 2021

I never really got the point of this issue - I'm confused by "Site A" and "Site B". Use Modchat for example and explain it again if you can.

Like, the site you are trying to log in might show you the code from another site, then log into that site as you.
And denial of service by constantly spamming verify.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants