appwrite / appwrite/appwrite

🐛 Bug Report: OAuth2 implementation does not enforce email retrieval

Open
#3,680 3 comments 0 reactions 0 assignees View on GitHub
bug product / auth
Dominant language
TypeScript
Stars
57.4k
Forks
5.7k
Avg merge
16h 27m
Merged PRs (30d)
291

Description

### 👟 Reproduction steps

Currently, when the user is presented with the Facebook oauth screen, the user can select 'Edit access" and then switch off the email.
![image](https://user-images.githubusercontent.com/1393766/184527584-f05ffa30-18ac-4021-9ba9-794c365e96b0.png)
![image](https://user-images.githubusercontent.com/1393766/184527591-7e2ad755-4f80-4ac8-908e-b06c2641a423.png)
This means that, after the user disables the email and clicks Continue, a new user will be created in Appwrite but without an email address.

Similar thing is happening with the Yandex OAuth2 adapter - users are created but without email address.

Discord post - https://discord.com/channels/564160730845151244/564175717521424424/1007611652750970900

### 👍 Expected behavior

Appwrite should extend the OAuth2 adapters to always enforce the retrieval of email address

### 👎 Actual Behavior

Users are created without an email address

### 🎲 Appwrite version

Version 0.15.x

### 💻 Operating system

Windows

### 🧱 Your Environment

_No response_

### 👀 Have you spent some time to check if this issue has been raised before?

- [X] I checked and didn't find similar issue

### 🏢 Have you read the Code of Conduct?

- [X] I have read the [Code of Conduct](https://github.com/appwrite/appwrite/blob/HEAD/CODE_OF_CONDUCT.md)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.