Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace usage of api with read_api in getAuthorizationUrl #25

Closed
garbast opened this issue May 26, 2021 · 5 comments · May be fixed by #53
Closed

Replace usage of api with read_api in getAuthorizationUrl #25

garbast opened this issue May 26, 2021 · 5 comments · May be fixed by #53

Comments

@garbast
Copy link
Contributor

garbast commented May 26, 2021

Using api scope, while the same can be achieved with read_api, gives to many rights that are not needed.

This could be reduced in

'scope' => ['api', 'read_user', 'openid']

@infabo
Copy link
Contributor

infabo commented Jun 2, 2021

+1

@zenobio93 zenobio93 self-assigned this Jan 17, 2022
@garbast
Copy link
Contributor Author

garbast commented Oct 10, 2023

Where do we go from here with this request?

@christian-fries
Copy link

Because the change of the scope is a breaking change, I propose to target a new major version

@garbast
Copy link
Contributor Author

garbast commented Dec 23, 2024

Sadly this issues was ignored for 2 1/1 years for now. Seams to not be relevant for the extension author.

@garbast garbast closed this as completed Dec 23, 2024
@infabo
Copy link
Contributor

infabo commented Dec 24, 2024

Because the change of the scope is a breaking change, I propose to target a new major version

Requiring less permissions is not a breaking change. All existing applications would work flawlessly with full "api" permissions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants