Justin Case @thieflord.dev · 08/01/2026That's fair, but we wanted to keep the price point low for barrier of entry. There are additional tiers that people can donate more than $5. 030
Reposted by Justin CaseClearsky App @clearsky.app · 07/01/2026We are actively working to bring down current costs and optimize infrastructure. We appreciate the feedback, assistance, and support. #Clearsky 53913
Justin Case @thieflord.dev · 07/01/2026We get $.61 for every $1 donated so we are only asking for $3k. Our DB is the bulk of the costs, ~$2k and ~5TB of data. It is a managed instance. We have been transparent and haven't done anything shady so it's strange for people to assume that's what's going on initially. 461
Justin Case @thieflord.dev · 07/01/2026I'm open to suggestions on how to make things more efficient. 430
Justin Case @thieflord.dev · 07/01/2026You know we don't get exactly $1 from the donation, right? The costs isn't $5000/mo. 100
Justin Case @thieflord.dev · 27/11/2025All high roads have been taken, it's a traffic jam up there. 081
Justin Case @thieflord.dev · 18/11/2025And the only consequence is the user decides not to log in. The security of the implementation is sound. 230
Justin Case @thieflord.dev · 18/11/2025We've already dropped down in permissions. This is a none issue now. 130
Justin Case @thieflord.dev · 18/11/2025This is a clash of the "privacy" userbase and "data transparency" userbase. Sit back and get some popcorn. 050
Justin Case @thieflord.dev · 17/11/2025Initially, people begged for these features to be behind a login. 230
Justin Case @thieflord.dev · 17/11/2025It won't send the sensitive authorization code to an unapproved location. Additionally, all of our communication uses HTTPS, and Bluesky's OAuth implementation enforces the use of the state parameter and PKCE (Proof Key for Code Exchange) to prevent code interception and session hijacking. 000
Justin Case @thieflord.dev · 17/11/2025If an attacker tried to swap the link, Bluesky's server would reject the request or refuse to redirect the user to the malicious URL. even if a malicious link were somehow injected onto our site, the Bluesky server controls the redirection. 100
Justin Case @thieflord.dev · 17/11/2025We mitigate this using strict redirect URI validation, we have pre-registered a specific, exact URL with Bluesky (the Authorization Server). When you start the login, we tell Bluesky: "After the user authorizes access, only send them back to this exact, pre-registered address." 100
Justin Case @thieflord.dev · 17/11/2025I am disappointed but not surprised. We are working to bring services to the community so that you are informed about your data. We appreciate all the support people have given and we are learning from the criticism. 1384
Reposted by Justin CaseErin Biba @erinbiba.bsky.social · 17/11/2025A looottttaaaa people in replies complaining and being down right nasty about a free service that someone has dedicated a ton of their time to simply to help you have more transparency about your account, which they absolutely did not have to do! Y’all have an astonishing sense of entitlement! 616130
Justin Case @thieflord.dev · 17/11/2025There is a difference between something being ready and you being upset that those are the permissions. The implementation is ready and working. 020
Justin Case @thieflord.dev · 17/11/2025Literacy is dead because why would you used quotes for something you weren't quoting what someone said verbatim. We asked you we error were you seeing and you didn't reply. 120
Justin Case @thieflord.dev · 17/11/2025It is ready. The current OAuth implementation is secure, that's what we've been explaining. And we also have updated the permissions that are being asked when you log in. 010
Justin Case @thieflord.dev · 17/11/2025I appreciate your kind words and sticking your neck out for me 🫶🏿 2160
Reposted by Justin CaseMark X @markmx.bsky.social · 17/11/2025The larger non specialized/technical user base is already using OAuth. It’s your early/technical adopters that you are experiencing friction with. I really disagree with the framing of this as a problem with OAuth and not app passwords 192
Justin Case @thieflord.dev · 17/11/2025I tried to use just "atproto" and I just tried again and I get this error: "The remote endpoint returned an error: Scope "transition:generic" is not declared in the client metadata" 110
Justin Case @thieflord.dev · 17/11/2025I tried to use just "atproto" and I just tried again and I get this error: "The remote endpoint returned an error: Scope "transition:generic" is not declared in the client metadata" 100
Justin Case @thieflord.dev · 17/11/2025That is the only permission set available, which is stated in the thread. We understand if you want to wait until Bluesky is done with adding the smaller permission scopes. We plan to drop down to the least permissions as soon as they are available. 320
Justin Case @thieflord.dev · 17/11/2025That's not what we're saying. Logged out functionality is still available, just not for all features. 120
Justin Case @thieflord.dev · 17/11/2025That is the only permission set available, which is stated in the thread. We understand if you want to wait until Bluesky is done with adding the smaller permission scopes. We plan to drop down to the least permissions as soon as they are available. 120
Justin Case @thieflord.dev · 17/11/2025This may not be what you wanted. We see the feedback and we are working on a plan. 150
Justin Case @thieflord.dev · 17/11/2025You made 6 replies that had incorrect information. We are replying to those posts adding the information and context. We are not hiding what we are doing or our plans; logging in has always been on the todo lists. This may not be what you wanted. We see the feedback and we are working on a plan. 100
Justin Case @thieflord.dev · 17/11/2025We are responding to misinformation about App passwords being more secure. 100
Justin Case @thieflord.dev · 17/11/2025More than half of the features on Clearsky are premium, required post processing and we've been offering them for free for years. We would love for our users to support us so we can continue to keep these services free. 110
Justin Case @thieflord.dev · 17/11/2025My hope is this explains how logging in works and how we use it to people that are confused and misinformed. Visit our FAQ to see the entire uninterrupted post. 130
Reposted by Justin CaseClearsky App @clearsky.app · 17/11/2025🧵 Understanding Authorization: OAuth vs. App Passwords 🔐 Your security is our top priority. We're explaining why OAuth is the most secure foundation for our new login features, even with current Bluesky limitations. 1/12 12511
Justin Case @thieflord.dev · 17/11/2025That is the only permission set available right now. Bluesky said they are working on more restrictive permissions. We will drop down to those when they are available. We already said that in a post. This service costs money to run, please support us and the ads can go away. 010
Justin Case @thieflord.dev · 17/11/2025More than half of the features on Clearsky are premium, required post processing. OAuth isn't insecure and the site isn't more insecure because we having logging in. We will be making a post to provide more information about OAuth and permissions because a lot of people are misinformed. 200
Justin Case @thieflord.dev · 17/11/2025That isn't true lol. The only thing that ticket says is, "Integrate logging in to bsky account using OAuth so we can utilize features that require auth API endpoints." 000
Justin Case @thieflord.dev · 16/11/2025You can see features in the works here: github.com/ClearskyApp0...github.comGitHub - ClearskyApp06/ClearskyUIContribute to ClearskyApp06/ClearskyUI development by creating an account on GitHub. 100
Justin Case @thieflord.dev · 16/11/2025The twexit debacle is the reason we have not implemented logging in until now. It's always been in the plans to do. With OAuth, we feel comfortable having users log in at this point. 271