5 ms·
Can I complain a bit about GitHub? Why I can only authorize my entire GitHub account for third-party access? Could things be slightly better if the authorizatio
by rqs 7y ago
Can I complain a bit about GitHub? Why I can only authorize my entire GitHub account for third-party access? Could things be slightly better if the authorization is done at repository level?
- Sukram21 7y agoGitHub provides a way for more granular third-party access: GitHub Apps. There, access can be set on a repository level [1]. E.g. Netlify can be configured as a GitHub app. It seems like Docker Hub is implemented as an OAuth app [2], where these granular options are not available and you have to grant access to all your repositories. [1] https://developer.github.com/apps/differences-between-apps/ https://developer.github.com/apps/differences-between-apps/ [2] https://docs.docker.com/docker-hub/builds/link-source/ https://docs.docker.com/docker-hub/builds/link-source/
- andy_ppp 7y agoYou can implement OAuth per repo if github wanted though, or alternatively can you grant access to a specific organisation? Not sure. The default should be per repo auth IMO.
- mmmeff 7y agoHoly shit this is a crazy attack vector.
- matthewaveryusa 7y agoI just looked at github OAuth scopes ( https://developer.github.com/apps/building-oauth-apps/understanding-scopes-for-oauth-apps/ https://developer.github.com/apps/building-oauth-apps/unders... ) honest question, what's the point of using OAuth when the Authz is so coarse? Why not augment to have scopes per repo? Is it considered bad practice to have have a variable (repo name) as a scope?
- nickgros 7y agoIIRC the OAuth2-interfacing application needs to (or at least should) know beforehand exactly what to request access to, so if that's read/write access to all of the user's content, it's trivial. For the external application to know something specific like a particular resource is more complicated to deal with (especially with private/hidden content), so most OAuth providers don't provide that level of granularity. It can be done, it just requires more engineering than most (all?) off-the-shelf OAuth solutions provide, and it's more control than most users actually need.
- QuinnyPig 7y agoOr to take it a step further, let me override which permissions I grant during the OAuth request.
- tomjakubowski 7y agoGitHub supports finer-grained permissions now via "Apps". https://developer.github.com/apps/differences-between-apps/ https://developer.github.com/apps/differences-between-apps/ https://www.netlify.com/docs/github-permissions/ https://www.netlify.com/docs/github-permissions/
- martinp 7y agoAgree, it's terrible if you just want automatic builds. I almost gave up on automatic Docker image push on one of my projects [1] earlier this year, when GitHub services were deprecated. Luckily I found a way to have Travis push the image instead [2]. It involves giving Travis my Docker Hub password (encrypted), but it's certainly better than granting some service full access to my GitHub account. [1] https://github.com/mpolden/echoip https://github.com/mpolden/echoip [2] https://docs.travis-ci.com/user/docker/#pushing-a-docker-image-to-a-registry https://docs.travis-ci.com/user/docker/#pushing-a-docker-ima...
- tobias3 7y agoIn my case I don't even know why it needs read and WRITE access to ALL repositories. All I want is for it to build one public repository. It doesn't need any special permissions for that at all.
- tedmiston 7y agoYou can authorize specific orgs your account has access to vs your whole account if that's what you're looking for. Also not sure what access permissions you need but deploy keys are repo level. https://developer.github.com/v3/guides/managing-deploy-keys/#deploy-keys https://developer.github.com/v3/guides/managing-deploy-keys/... Machine users are another option. https://developer.github.com/v3/guides/managing-deploy-keys/#machine-users https://developer.github.com/v3/guides/managing-deploy-keys/...
- neovatar 7y agoSeems that dockerhub is using the github oauth permissions to do three things: - retrieve a list of all repos to display in the autobuild setup page - setup webhooks for the gh repo that should be built via dockerhub autobuild - setup a deploy key for said repo, so that it can be cloned I removed the dockerhub oauth on github side, after setting up autobuild. My builds on push to master and tag are still working. So it seems possible to remove dockerhubs write access to your github repos after the autobuild setup, which really seems to be a good idea.
- sigotirandolas 7y agoI found this snippet on Docker Hub's Linked Account Settings: > Service user (or machine/bot account) suggested > Attaching your personal GitHub or Bitbucket account to this Docker Hub organization will allow other organization owners to create builds from your private repositories. We suggest using a service user (also referred to as a machine user or bot account). c.f.: https://docs.docker.com/docker-cloud/builds/automated-build/#service-users-for-team-autobuilds https://docs.docker.com/docker-cloud/builds/automated-build/... Seems worthwhile to do this, if you're an enterprise or otherwise have sensitive private repos. But I agree that it would be better to have an easier per-repo authorization system, since many users won't bother going through the hassle of setting up a service account.
- windexh8er 7y ago> > Attaching your personal GitHub or Bitbucket account to this Docker Hub organization will allow other organization owners to create builds from your private repositories. We suggest using a service user (also referred to as a machine user or bot account). > c.f.: https://docs.docker.com/docker-cloud/builds/automated-build/.. https://docs.docker.com/docker-cloud/builds/automated-build/.... Did they remove this language from your link? I don't see it anymore.