Skip to content

scopes for github oauth #29

Description

@memen45

+ '&scope=' + encodeURIComponent('user repo notifications')

In this line more access is requested compared to what is described in settings. Should it not be read:user user:email notifications instead to be more specific?

As mentioned in the "connected accounts" GitHub settings hint, you should check "read:user", "user:email" and "notifications" permissions.

Originally posted by @eneiluj in #18 (comment)

Activity

  1. added a commit that references this issue on Sep 1, 2021
  2. julien-nc commented on Sep 1, 2021

    @julien-nc
    Member

    Yes well, when using OAuth, we request more scopes than when using a personal token. It's not a big deal as the app never makes any action which require the user:follow permission.

    Keep in mind that the instructions in the settings are for personal tokens and the line you mention is about the scopes that are required when getting a token via OAuth.

    Did I understand your concern?

    Anyway, for security reasons, let's limit the OAuth scopes as much as possible, you're right. it's done and pushed. It will be included in the next release.

  3. memen45 commented on Sep 1, 2021

    @memen45
    Author

    Yes, indeed, both scopes repo and user:follow are not used then, right?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions