AnswerDotAI / AnswerDotAI/fasthtml-example
OAuth example should not infer org affiliation from the email field.
- Dominant language
- CSS
- Stars
- 854
- Forks
- 130
- PR merge metrics
- No merged PRs in 30d
Description
This example parses the user's email, returned from Google's authorization server, in order to determine if the user should have access:
https://github.com/AnswerDotAI/fasthtml-example/blob/6a985a7d00ff33a54a07aa9ff9a8dba77bbeb428/oauth_example/oa.py#L9
However, Google says not to do this, and to use the "hd claim" instead:

We should update the example to follow Google's advice.
An analogous change will also be needed in the fasthtml explainer notebook: https://github.com/AnswerDotAI/fasthtml/blob/main/nbs/explains/oauth.ipynb
It may appear elsewhere as well.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with oauth_example/oa.py at the linked line, then inspect nbs/explains/oauth.ipynb for the analogous email-based affiliation check. Search the example repository and explainer for other uses of the email field in access decisions. Done means both examples follow Google's hd claim guidance and no email-based organization inference remains.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- jupyter-notebook, python
- Domain
- authentication, authorization
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100