4 ms·
Hey Mike, We don't ever write anything to your profile. As explained in the link below, this is a standard GitHub permission. PS your SSH keys are 100% public
by mydigitalself 13y ago
Hey Mike,
We don't ever write anything to your profile. As explained in the link below, this is a standard GitHub permission.
PS your SSH keys are 100% public:
https://api.github.com/users/mikexstudios/keys https://api.github.com/users/mikexstudios/keys
Mike
Short answer: https://gitter.zendesk.com/hc/en-us/articles/200178961-Why-do-you-ask-for-write-access-to-my-profile- https://gitter.zendesk.com/hc/en-us/articles/200178961-Why-d...
Long answer: https://gitter.zendesk.com/hc/en-us/articles/200176672-Authenticating-with-GitHub https://gitter.zendesk.com/hc/en-us/articles/200176672-Authe...
- misterdai 13y agoAny idea if GitHub will ever alter the way that works so you can avoid it giving you write access. I was all ready to give Gitter a go until I saw the permissions that would be granted. Sure you're trust worthy but us IT types can be paranoid ;-)
- mydigitalself 13y agoThey actually recently announced some more granular scopes for working with webhooks. So we hope for more to come for other areas of the API.
- suprememoocow 13y agoHi, this is Andrew from Gitter. And we completely understand. We're waiting on Github to update their OAuth scopes, and we understand that they're working on it. If you're not comfortable with the OAuth permissions Gitter requires, you could try Gitter's sister product, Troupe https://trou.pe https://trou.pe. It's got most of the same features, but with less Github integration and no markdown or syntax highlighting.
- dereferenced 13y agoYou could always be hacked. It's a danger to provide those permissions. (I understand that there's not much more you can do about it.)
- songgao 13y agoThe idea that this gives write access to my SSH keys is still scary. Not that I don't trust your service, but what if somebody attacks it and adds malicious keys? Or does write access not include SSH keys?