Skip to content

Revoke all scopes on gh auth refresh without --scope #6785

Description

@scarf005

Describe the feature or problem you’d like to solve

HTTP 403: Must have admin rights to Repository. (https://api.github.com/repos/scarf005/pyvips)
This API operation needs the "delete_repo" scope. To request it, run:  gh auth refresh -h github.com -s delete_repo

after repo deletion, I wanted to revoke delete_repo scope given with gh auth refresh, since I did not want to accidently delete repos.

The --scopes flag accepts a comma separated list of scopes you want your gh credentials to have. If absent, this command ensures that gh has access to a minimum set of scopes.

I ran gh auth refresh again as the description in cli doc said.

image

but to my surprise cli still had access to repository deletion. as said in #5083, current way to revoke github cli's scope is to completely de-authorize github cli app. this is very inconvenient.

Proposed solution

gh repo request should follow the documentation and revoke access to the point of minimum set of scopes.
in this example, Delete Repositories access should be revoked.

Discussed in #5083

Originally posted by pritambera2000 January 23, 2022
How to revoke scopes on gh auth refresh . After granting a scope can't revoke it from cli

Activity

  1. added
    discussFeature changes that require discussion primarily among the GitHub CLI team
    on Jan 3, 2023
  2. vilmibm commented on Jan 9, 2023

    @vilmibm
    Contributor

    Definitely agreed that there should be the ability to remove scopes via this command.

    Let's use this issue to cover the addition of two new flags:

    # Remove a single scope
    gh auth refresh --remove-scope '<scope>'
    
    # Reset to gh's default scopes
    gh auth refresh --reset-scopes
    
  3. added and removed
    discussFeature changes that require discussion primarily among the GitHub CLI team
    on Jan 9, 2023
  4. n1lesh commented on May 14, 2023

    @n1lesh
    Contributor

    @mislav @vilmibm I would like to work on it, if it's still open.

    Also, would it make sense to rather have a --remove-scopes to allow removing multiple scopes at once?

  5. samcoe commented on May 14, 2023

    @samcoe
    Contributor

    @n1lesh There are no open PRs for this feature so please feel free to work on it. The --remove-scope flag should allow for multiple values to be specified. We do not want to add both --remove-scope and --remove-scopes flags, one is sufficient.

  6. n1lesh commented on Jun 18, 2023

    @n1lesh
    Contributor

    @samcoe @vilmibm @mislav Is there an API to revoke all or at least remove a set of scopes? The current refresh flow with only minimum scopes still retains the previously added additional scopes (for eg read:public_key).

    I understand that scope can be revoked under https://github.com/settings/connections/applications/* but is there a way to actually clear out scopes through the API?

  7. samcoe commented on Jun 19, 2023

    @samcoe
    Contributor

    @n1lesh There is no endpoint for revoking scopes. The auth refresh works by creating a token with the given scopes. This feature should not need to modify that behavior at all, just needs to make sure the correct scopes are passed through to the current functionality.

  8. Shion1305 commented on Jun 19, 2023

    @Shion1305
    Contributor

    I find the 'gh auth refresh --remove-scope' command quite appealing. Would it be alright if I tackled this in a PR?
    I've mostly figured out the tasks involved.

  9. n1lesh commented on Jun 19, 2023

    @n1lesh
    Contributor

    @samcoe I think I was confused with the webflow showing Existing access scopes even though the access token doesn't have anything else except for the minimum required scopes after reset.

    Screenshot 2023-06-19 at 8 06 47 PM

    While the functionality works as expected after the change, would it be a good UX to still have existing access scopes shown
    in the browser flow but the resulting access token doesn't really have it?

  10. Shion1305 commented on Jun 19, 2023

    @Shion1305
    Contributor

    @n1lesh @samcoe @vilmibm

    Hi everyone,

    Firstly, I want to clarify that I am relatively new to contributing to open source and jumped into this more as an adventure. I certainly didn't mean to step on any toes or create any conflict.

    As I was finalizing my PR and preparing the documentation, I noticed that a PR had just been submitted by @n1lesh . I want to express my acknowledgment of their contribution and note that I'm completely fine if their PR is selected over mine.

    That said, I did spend a few hours on this and believe it might still offer some value to the project. So I thought it would be worthwhile to submit my PR as well. I look forward to your feedback and appreciate the opportunity to contribute to this project.

    Thank you for understanding.

  11. williammartin commented on Jun 22, 2023

    @williammartin
    Member

    Hi @Shion1305, thank you for your PR and your message. It is unfortunate that we have duplicated work here and I'm sorry that there wasn't a timely response to your original question about taking ownership. We appreciate your contribution either way.

    In terms of where we go from here, we'll likely review both PRs and draw together what we like from both. We will come back to you both with a path forward when we have reviewed. Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementa request to improve CLIhelp wantedContributions welcome

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions