webcompat.com icon indicating copy to clipboard operation
webcompat.com copied to clipboard

Github app permission does not affirmatively provide scope of permission

Open CharlesBelov opened this issue 3 years ago • 0 comments

https://github.com/webcompat / webcompat.com issue GitHub App permission #3626 states that Webcompat has been changed to a Github app and only requests permission for webcompat/web-bugs. However, when I try to log in to Webcompat or submit an issue, I get the message:

webcompat-app by WebCompat would like permission to: Verify your GitHub identity (CharlesBelov) Know which resources you can access Act on your behalf

with no mention of any repository restriction.

I would only feel comfortable granting this permission if GitHub specified that as scope.

CharlesBelov avatar Jul 22 '22 01:07 CharlesBelov