browser-extension icon indicating copy to clipboard operation
browser-extension copied to clipboard

Required permissions should be dialed down

Open asfaltboy opened this issue 9 years ago • 5 comments

The current content script domain url matching, shows a "scary" permission required message where all data on all sites is exposed to extension.

I'm sure some people would appreciate that the exposed sites will be github/bitbucket as the extension advertises, is there a reason for this change?.

asfaltboy avatar Sep 22 '15 13:09 asfaltboy

+1 - I just removed the extension because of this change. Seems unnecessary to not limit it to a list of sites.

ekweible avatar Sep 22 '15 14:09 ekweible

Thank you for the feedback. The reason for extending the privileges (and I agree in a "scary" manner) is because of customers using Codecov in self-hosted Enterprise mode.

I'll be creating a separate application for enterprise customers and place the privileges back to the minimum as it once was.

Meanwhile, the source code is (and will remain) open source in this repository.

stevepeak avatar Sep 22 '15 14:09 stevepeak

@stevepeak thank you for your transparency on this matter.

I too look forward to those permissions are dialed down to the minimal required for effective use of CodeCov with public code hosting platforms.

hutson avatar Nov 21 '15 05:11 hutson

Any chance this will be revisited?

AnthonyClark avatar May 30 '17 18:05 AnthonyClark

@stevepeak it's been two years now; do you intend to adjust the permissions back? The extension is extremely useful, but 9/10 times I recommend it to someone they don't install it because of this permissions request.

dmnd avatar Oct 24 '17 17:10 dmnd