17 ms·
I get that! In order to check out the repo, these permissions are required though. What could I do to make you feel comfortable granting those permissions?
by mlamina 3y ago
I get that! In order to check out the repo, these permissions are required though. What could I do to make you feel comfortable granting those permissions?
- bo0tzz 3y agoIt would be much better to allow granting access to only a single repository, rather than complete and absolute access to all the repositories in an account.
- mlamina 3y agoI hear you. I've posted a comment to address this concern
- haswell 3y agoComplete transparency and clarity about how data is used, stored, what systems get to see it, and minimizing privileges would be a starting point IMO. Ask yourself the same question: what would make you feel comfortable handing the keys to your GitHub account to me, haswell, for a tool that I decide to share here?
- mlamina 3y agoThank you! Based on the feedback I saw here, I'll create some diagrams and more details about how things work under the hood. Will also work on the privileges issue.
- justinclift 3y agoPlease make sure it doesn't request access to private repos. That would be far more considerate of your potential users.
- dash2 3y agoIt said it needed read and write access to my email. I don't think it should even need read access. I probably wouldn't mind giving you my email separately as a signup.
- mlamina 3y agoThat was definitely not my intention. I'll take a closer look at the permissions.
- justinclift 3y ago> What could I do to make you feel comfortable granting those permissions? Literally nothing. Ain't gunna happen. :( :( :(
- nox101 3y agoI wish all devs on github had this attitude. 9 out of 10 github integrations ask for blanket permission to do everything to all repos and 4 out of 5 library devs give them those permissions. It's a a bunch supply-side breaches waiting to happen. IMO, I think I feel like github should be ashamed for even making it possible to ask for blanket permissions. I think they should have designed their permission system to make it harder to do such a thing. Like maybe it shows a list of repos and asks "which ones, which permissions per, etc...". Not sure if that's enough but I think they need to do more. As it is, the easiest path for a company to integrate with github is to ask for blanket permissions because then they can setup and/or add any hooks etc automatically. No work on the user's part. But, that contributes to making the entire infrastructure of the world less secure (because much of the world's infrastructure depends on these repos) and it feels irresponsible for github to indirectly encourage it.
- erhaetherth 3y agoFWIW, when I integrate APIs, I always try to ask for as little as possible. Years ago I was trying to integrate some 3rd party logins and they're all trying to give me the user's email address. I'm like I don't even need that, just give me a unique identifier I can throw in my DB. Nothing more. Better yet, I should be able to request a list of "required" permissions and "optional" permissions. Sometimes optional stuff is handy for optional features or to prefill stuff for the user to make it easier on them but not required for the app to function.