3 ms·
How come the application needs write permissions to repos (private and public)?
by mackwerk 12y ago
How come the application needs write permissions to repos (private and public)?
- makmanalp 12y agoYeah, I was super excited until I saw this - write perms to repos and personal info. Especially since I use github for work and admin a bunch of repos, I can't take the risk of allowing write access.
- bbrunner 12y agoUnfortunately, as far as I can tell, there isn't any way to specifically ask for only read permissions for private repos. The commit statuses permission doesn't allow for listing of private repos either. If I'm completely missing something than I'd be more than happy to get a change deployed.
- curun1r 12y agoJudging by the screenshots of the product, it seems like repo:status is the permission that you should be asking for instead of repo. It's still read/write, but only to commit statuses and not code. Is there something that your product is doing that requires read access to the code?
- bbrunner 12y agoI tried repo:status but from my testing I wasn't able to list private repos. So even though I might be able to get their commits I had no way of discovering all of the private repos for a person/org. I'll reinvestigate this as soon as I'm off the caltrain and have decent internet :)
- res0nat0r 12y agoI think r/w access is due to a limitation in the permissions from Github. Hopefully they will make this more fine-grained soon. https://slack.zendesk.com/hc/en-us/articles/201824286-Why-does-Slack-need-read-write-access-to-all-of-my-GitHub-repos- https://slack.zendesk.com/hc/en-us/articles/201824286-Why-do...
- 100k 12y agoI wish GitHub would add more fine-grained permissions. Right now authorizing an app like this is giving away the keys to the kingdom and that's a little scary. For a similar reason we chose to run Hound (https://houndci.com/ https://houndci.com/) locally instead of use the SaaS version.
- masklinn 12y ago> I wish GitHub would add more fine-grained permissions. Yes, for both API and direct access. You can't allow somebody to triage bugs without giving them write access to the repository itself.
- agilebyte 12y agoCould you ask for either public or private scope?
- IanCal 12y agoThere doesn't seem to be such a thing in github, at least there wasn't last time I had to deal with this. If they've updated it since then that'd be awesome, but I think this is a long-standing issue.
- agilebyte 12y agoI see, you are right you could only do ` ` to get some information and `public_repo` grants write access too. https://developer.github.com/v3/oauth/#scopes https://developer.github.com/v3/oauth/#scopes