coder13 / coder13/LetsCube

Add privacy-safe cuber discovery and public profiles

Open
#82 0 comments 0 reactions 1 assignee Claimed by @coder13 View on GitHub
area: auth area: social enhancement priority: P1
Dominant language
JavaScript
Stars
30
Forks
9
PR merge metrics
No merged PRs in 30d

Description

## Goal

Help authenticated cubers find someone they already know or raced with and open a safe public profile before sending a friend request.

## MVP discovery contract

- Search only by normalized username and, when the target has explicitly enabled WCA identity visibility, WCA ID.
- Never search by email, ingest email for this feature, accept email as an identifier, or reveal whether an email exists.
- Require authentication, enforce bounded/rate-limited queries, and return a capped paginated result set.
- Respect blocks and profile visibility without telling a blocked user that a block caused an omitted result.
- Support entry points from the lobby user list, room users/times/chat, the friends hub, and direct username search.
- Do not add algorithmic stranger recommendations in the MVP.

## Public profile contract

Use one explicit server-side public projection containing only fields the viewer may see:

- stable public user identifier;
- display name and username;
- WCA identity and WCA-hosted avatar only when the target opted to reveal them;
- viewer-relative friend state: none, outgoing request, incoming request, or friends;
- relevant actions: request/cancel/accept/decline/unfriend/block and invite when eligible.

Do not reuse the editable `/profile` response for another user, and never include access tokens, email, hidden real name/WCA ID, private preferences, private-room membership, friend graph, or notification data.

## Acceptance criteria

- [ ] Add authenticated, indexed user search backed by #185's normalized username field.
- [ ] Add an authenticated public-profile endpoint and `/users/:id` client route with explicit field projection.
- [ ] Make user names/avatars open the public profile from existing lobby and room surfaces without breaking timer interaction or mobile layouts.
- [ ] Show correct viewer-relative friendship actions using #75 and handle concurrent/stale transitions.
- [ ] Return stable empty, not-found/unavailable, blocked, rate-limited, loading, and error states without user-enumeration leaks.
- [ ] Add server tests for every visibility combination, email-like queries, blocks, pagination, ID tampering, and unauthenticated access.
- [ ] Add client tests for hidden/visible WCA identity, friend states, keyboard accessibility, and responsive layouts.
- [ ] Add a two-user Cypress flow for search → profile → friend request.

## Dependencies

- #185 normalized username migration
- #191 email removal/purge
- #75 friendship lifecycle

## Deferred

- Opt-in language/timezone/event/pace matching is tracked in #190.
- Solve history, PBs, and rankings depend on the results-history work and are not required for this MVP.
- Public unauthenticated profiles are out of scope.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.