Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Add privacy-safe cuber discovery and public profiles

未关闭
#82 0 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

@coder13 已经在做这个了。

开始于 2021年4月7日。

评估

这个 Issue 还没有评估数据。

描述

area: auth area: social enhancement priority: P1

Goal

Help authenticated cubers find someone they already know or raced with and open a safe public profile before sending a friend request.

MVP discovery contract

  • Search only by normalized username and, when the target has explicitly enabled WCA identity visibility, WCA ID.
  • Never search by email, ingest email for this feature, accept email as an identifier, or reveal whether an email exists.
  • Require authentication, enforce bounded/rate-limited queries, and return a capped paginated result set.
  • Respect blocks and profile visibility without telling a blocked user that a block caused an omitted result.
  • Support entry points from the lobby user list, room users/times/chat, the friends hub, and direct username search.
  • Do not add algorithmic stranger recommendations in the MVP.

Public profile contract

Use one explicit server-side public projection containing only fields the viewer may see:

  • stable public user identifier;
  • display name and username;
  • WCA identity and WCA-hosted avatar only when the target opted to reveal them;
  • viewer-relative friend state: none, outgoing request, incoming request, or friends;
  • relevant actions: request/cancel/accept/decline/unfriend/block and invite when eligible.

Do not reuse the editable /profile response for another user, and never include access tokens, email, hidden real name/WCA ID, private preferences, private-room membership, friend graph, or notification data.

Acceptance criteria

  • Add authenticated, indexed user search backed by #185's normalized username field.
  • Add an authenticated public-profile endpoint and /users/:id client route with explicit field projection.
  • Make user names/avatars open the public profile from existing lobby and room surfaces without breaking timer interaction or mobile layouts.
  • Show correct viewer-relative friendship actions using #75 and handle concurrent/stale transitions.
  • Return stable empty, not-found/unavailable, blocked, rate-limited, loading, and error states without user-enumeration leaks.
  • Add server tests for every visibility combination, email-like queries, blocks, pagination, ID tampering, and unauthenticated access.
  • Add client tests for hidden/visible WCA identity, friend states, keyboard accessibility, and responsive layouts.
  • Add a two-user Cypress flow for search → profile → friend request.

Dependencies

  • #185 normalized username migration
  • #191 email removal/purge
  • #75 friendship lifecycle

Deferred

  • Opt-in language/timezone/event/pace matching is tracked in #190.
  • Solve history, PBs, and rankings depend on the results-history work and are not required for this MVP.
  • Public unauthenticated profiles are out of scope.
主要语言
JavaScript
星标
29
派生
9
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 提供 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

coder13/LetsCube 的其他 Issue

查看 coder13/LetsCube 的全部 Issue

相似的 Issue

更多 JavaScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。