Skip to content

Oauth2 missing permission/security warning #1683

Description

@Rotzbua

Problem

The oauth2 documentation does not state which permissions are granted to an external service.
It just mention "connecting" and do not warn about possible security and data leaks.

Nextcloud allows connecting external services (for example Moodle) to your Nextcloud.

Solution

  • Add a list of permissions.
  • Add a security warning.

Current documentation

https://docs.nextcloud.com/server/17/admin_manual/configuration_server/oauth2.html

Activity

  1. skjnldsv commented on Oct 25, 2019

    @skjnldsv
    Member
  2. rullzer commented on Oct 25, 2019

    @rullzer
    Member

    Feel free to submit a PR with better wording.
    By default you just get an access token and have full access.

  3. added a commit that references this issue on Jan 21, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions