coder13 / coder13/LetsCube

Add privacy-safe cuber discovery and public profiles

Abierto
#82 0 comentarios 0 reacciones 1 asignado Reclamado por @coder13 Ver en GitHub
area: auth area: social enhancement priority: P1
Lenguaje dominante
JavaScript
Estrellas
30
Forks
9
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

## Goal

Help authenticated cubers find someone they already know or raced with and open a safe public profile before sending a friend request.

## MVP discovery contract

- Search only by normalized username and, when the target has explicitly enabled WCA identity visibility, WCA ID.
- Never search by email, ingest email for this feature, accept email as an identifier, or reveal whether an email exists.
- Require authentication, enforce bounded/rate-limited queries, and return a capped paginated result set.
- Respect blocks and profile visibility without telling a blocked user that a block caused an omitted result.
- Support entry points from the lobby user list, room users/times/chat, the friends hub, and direct username search.
- Do not add algorithmic stranger recommendations in the MVP.

## Public profile contract

Use one explicit server-side public projection containing only fields the viewer may see:

- stable public user identifier;
- display name and username;
- WCA identity and WCA-hosted avatar only when the target opted to reveal them;
- viewer-relative friend state: none, outgoing request, incoming request, or friends;
- relevant actions: request/cancel/accept/decline/unfriend/block and invite when eligible.

Do not reuse the editable `/profile` response for another user, and never include access tokens, email, hidden real name/WCA ID, private preferences, private-room membership, friend graph, or notification data.

## Acceptance criteria

- [ ] Add authenticated, indexed user search backed by #185's normalized username field.
- [ ] Add an authenticated public-profile endpoint and `/users/:id` client route with explicit field projection.
- [ ] Make user names/avatars open the public profile from existing lobby and room surfaces without breaking timer interaction or mobile layouts.
- [ ] Show correct viewer-relative friendship actions using #75 and handle concurrent/stale transitions.
- [ ] Return stable empty, not-found/unavailable, blocked, rate-limited, loading, and error states without user-enumeration leaks.
- [ ] Add server tests for every visibility combination, email-like queries, blocks, pagination, ID tampering, and unauthenticated access.
- [ ] Add client tests for hidden/visible WCA identity, friend states, keyboard accessibility, and responsive layouts.
- [ ] Add a two-user Cypress flow for search → profile → friend request.

## Dependencies

- #185 normalized username migration
- #191 email removal/purge
- #75 friendship lifecycle

## Deferred

- Opt-in language/timezone/event/pace matching is tracked in #190.
- Solve history, PBs, and rankings depend on the results-history work and are not required for this MVP.
- Public unauthenticated profiles are out of scope.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.