Repository navigation
Revoke all scopes on gh auth refresh without --scope #6785
Description
Activity
- addeddiscussFeature changes that require discussion primarily among the GitHub CLI teamFeature changes that require discussion primarily among the GitHub CLI team
on Jan 3, 2023 Definitely agreed that there should be the ability to remove scopes via this command.
Let's use this issue to cover the addition of two new flags:
# Remove a single scope gh auth refresh --remove-scope '<scope>' # Reset to gh's default scopes gh auth refresh --reset-scopesReacted by scarf- addedhelp wantedContributions welcomeContributions welcomeand removeddiscussFeature changes that require discussion primarily among the GitHub CLI teamFeature changes that require discussion primarily among the GitHub CLI team
on Jan 9, 2023 @n1lesh There are no open PRs for this feature so please feel free to work on it. The
--remove-scopeflag should allow for multiple values to be specified. We do not want to add both--remove-scopeand--remove-scopesflags, one is sufficient.Reacted by Nilesh Singh@samcoe @vilmibm @mislav Is there an API to revoke all or at least remove a set of scopes? The current refresh flow with only minimum scopes still retains the previously added additional scopes (for eg
read:public_key).I understand that scope can be revoked under
https://github.com/settings/connections/applications/*but is there a way to actually clear out scopes through the API?@n1lesh There is no endpoint for revoking scopes. The
auth refreshworks by creating a token with the given scopes. This feature should not need to modify that behavior at all, just needs to make sure the correct scopes are passed through to the current functionality.Reacted by Nilesh SinghI find the 'gh auth refresh --remove-scope' command quite appealing. Would it be alright if I tackled this in a PR?
I've mostly figured out the tasks involved.@samcoe I think I was confused with the webflow showing
Existing accessscopes even though the access token doesn't have anything else except for the minimum required scopes afterreset.
While the functionality works as expected after the change, would it be a good UX to still have existing access scopes shown
in the browser flow but the resulting access token doesn't really have it?Hi everyone,
Firstly, I want to clarify that I am relatively new to contributing to open source and jumped into this more as an adventure. I certainly didn't mean to step on any toes or create any conflict.
As I was finalizing my PR and preparing the documentation, I noticed that a PR had just been submitted by @n1lesh . I want to express my acknowledgment of their contribution and note that I'm completely fine if their PR is selected over mine.
That said, I did spend a few hours on this and believe it might still offer some value to the project. So I thought it would be worthwhile to submit my PR as well. I look forward to your feedback and appreciate the opportunity to contribute to this project.
Thank you for understanding.
Reacted by William Martin and NagabhushanSN24Hi @Shion1305, thank you for your PR and your message. It is unfortunate that we have duplicated work here and I'm sorry that there wasn't a timely response to your original question about taking ownership. We appreciate your contribution either way.
In terms of where we go from here, we'll likely review both PRs and draw together what we like from both. We will come back to you both with a path forward when we have reviewed. Thanks.
Reacted by Shion IchikawaReacted by Shion Ichikawa
Describe the feature or problem you’d like to solve
HTTP 403: Must have admin rights to Repository. (https://api.github.com/repos/scarf005/pyvips) This API operation needs the "delete_repo" scope. To request it, run: gh auth refresh -h github.com -s delete_repoafter repo deletion, I wanted to revoke
delete_reposcope given withgh auth refresh, since I did not want to accidently delete repos.I ran
gh auth refreshagain as the description in cli doc said.but to my surprise cli still had access to repository deletion. as said in #5083, current way to revoke github cli's scope is to completely de-authorize github cli app. this is very inconvenient.
Proposed solution
gh repo requestshould follow the documentation and revoke access to the point of minimum set of scopes.in this example,
Delete Repositoriesaccess should be revoked.Discussed in #5083
Originally posted by pritambera2000 January 23, 2022
How to revoke scopes on
gh auth refresh. After granting a scope can't revoke it from cli