3 ms·
Couldn't agree more... Do we really need to grant read and write access to all repos? Sucks if GH's scoping is that coarse.
by jgeewax 12y ago
Couldn't agree more... Do we really need to grant read and write access to all repos? Sucks if GH's scoping is that coarse.
- malandrew 12y agoUnfortunately Amazon is the only cloud provider out there with a robust ACL system. Is there an open industry standard for implementing ACL policies flexibly like the one Amazon has?
- garblegarble 12y agohttp://en.wikipedia.org/wiki/XACML http://en.wikipedia.org/wiki/XACML would be one - it can be a little complicated, but if you can get over that it's quite nice and also adds the idea of an Obligation (something that must be performed on a grant/deny - for example, logging/e-mailing)
- Wingman4l7 12y agoIt definitely isn't that coarse: https://developer.github.com/v3/oauth/#scopes https://developer.github.com/v3/oauth/#scopes
- VoxPelli 12y agoGitHub are also working on enabling users to accept just a subset of the requested scopes, like just access to public repos, which will make using all of the more fine-grained scopes easier: https://developer.github.com/changes/2013-10-04-oauth-changes-coming/ https://developer.github.com/changes/2013-10-04-oauth-change...
- hk__2 12y agoNo it’s not, you can make an app that have access only to your public info, and/or public repos, etc.
- stanzheng 12y agoI agree that breakdown should be more anonymized. Readme permission/gitignore/license/code should have different end permissions