Current problem
Discord has an OAuth scope called "join servers for you", and it allows apps to join servers for you. While this is a scam hazard, it is also an important scope and not all uses of it are malicious.
Discord also doesn't really do a good job of communicating that this scope may be dangerous.
Proposed change
I propose that Fluxer add "dangerous scopes", AKA, scopes that require an elevated permission level "sudo mode" to authorize. This will be the same pop-up modal as changing password or deleting account.
Then, alongside this, Fluxer could add a "join communities for you" scope that apps could use.
Additional information
Fluxer could also add a "send message as you" scope too. Risk of scammy / spammy, but there could be benevolent use cases, and furthermore, the sudo mode should discourage most scammers or malicious actors.
7 comments
Comment by @AvaLilac
Comment by tempest:squll.fartcore.ai
Comment by @sarthaksinha363
Comment by tempest:squll.fartcore.ai
Comment by @PilkeySEK
Comment by @PilkeySEK
Comment by tempest:squll.fartcore.ai