-
Notifications
You must be signed in to change notification settings - Fork 23
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Questionable permission level #138
Comments
Thanks for the report. It should only need;
The current permissions are set here -> https://github.com/jsonresume/jsonresume.org/blob/master/apps/registry/auth.js#L12 I will check it out later if no one else knows how to reduce those permissions |
Just need to change it to But I don't think it's possible to scope it to public gist only |
that seems to be included as the default: |
Yeah but it doesn't support writing gist which is needed for the editor |
Ah, okay. You are right. This would need the |
I've updated it to just read user profile in this commit 8e5b9dc Will keep this open for a little while to see if anyone has any good ideas to let people keep their gists private. |
Awesome! Thanks 👍🏻 |
What do you need that excessive permissions for? I thought, you just need to read from a simple gist?
The text was updated successfully, but these errors were encountered: