lichess.org
Donate

I found a legal exploit within the API

curl -X POST lichess.org/api/challenge/username -H "Authorization: Bearer api_code" -H "Content-Type: application/x-www-form-urlencoded" -H "Accept: application/json" -d "rated=false&clock.limit=0&clock.increment=0" where "username" is the username of the player you want to challenge and api_code is the api code you can get from lichess

This lets people challenge each other to 0+0 games when executed in cmd.exe, and in fact, a bunch of people have already done so. Now this doesn't abust infrastructure because it's not spamming games, and since the games were casual, it doesn't affect rating, and therefore isn't against the ToS that way either.

So effectively, when done right, this is a legal way to send cursed challenges.

Similarly, in Swiss tournaments, inspect element to set the time to 0+[high number around 512] also results in 0+0 games.

I reported this in the discord too, with no response, so I'm reporting it here with hopes of a response from a mod or developer.
@F360r The bug has apparently been fixed. I think some of the 0+0 games of the past may still remain, though.

This topic has been archived and can no longer be replied to.