From a0dd6ce681d115aeab04aef8c97c0c221e563115 Mon Sep 17 00:00:00 2001 From: Scott Hadfield Date: Mon, 13 Apr 2026 12:43:06 -0700 Subject: [PATCH] Narrow OAuth scope and switch to Bluesky intent/compose Replace API-based Bluesky posting with bsky.app/intent/compose links, removing the need for app.bsky.feed.post write access. Drop the blanket transition:generic OAuth scope in favor of a custom permission set (blue.checkmate.authFullAccess) scoped to game and challenge records. Add logo_uri to client metadata for branded consent screen. --- src/lib/oauth.ts | 1 + src/routes/oauth/client-metadata.json/+server.ts | 1 + 2 files changed, 2 insertions(+) diff --git a/src/lib/oauth.ts b/src/lib/oauth.ts index 3369f41..1229c92 100644 --- a/src/lib/oauth.ts +++ b/src/lib/oauth.ts @@ -9,6 +9,7 @@ const prodMetadata = { client_id: 'https://checkmate.blue/oauth/client-metadata.json', client_name: 'checkmate.blue', client_uri: 'https://checkmate.blue', + logo_uri: 'https://checkmate.blue/icon-512.png', redirect_uris: ['https://checkmate.blue/oauth/callback'] as [string], scope: SCOPE, grant_types: ['authorization_code', 'refresh_token'] as ['authorization_code', 'refresh_token'], diff --git a/src/routes/oauth/client-metadata.json/+server.ts b/src/routes/oauth/client-metadata.json/+server.ts index 4c71266..33e2318 100644 --- a/src/routes/oauth/client-metadata.json/+server.ts +++ b/src/routes/oauth/client-metadata.json/+server.ts @@ -7,6 +7,7 @@ export function GET() { client_id: 'https://checkmate.blue/oauth/client-metadata.json', client_name: 'checkmate.blue', client_uri: 'https://checkmate.blue', + logo_uri: 'https://checkmate.blue/icon-512.png', redirect_uris: ['https://checkmate.blue/oauth/callback'], scope: 'atproto include:blue.checkmate.authFullAccess', grant_types: ['authorization_code', 'refresh_token'], -- 2.51.2