Can I change app permissions when authorizing Github Apps? #140199
Replies: 5 comments
|
push |
|
hey @florianmartens, github apps use fine-grained permissions that are defined during installation. unfortunately, you can't modify those permissions dynamically when authorizing users. oauth tokens and scopes behave differently from github apps, and scopes won’t override the app’s global permission settings. make sure you're not mixing up oauth app scopes and github app permissions during setup https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/scopes-for-oauth-apps hope that helps! feel free to mark it as an answer if useful! 😄 |
|
🕒 Discussion Activity Reminder 🕒 This Discussion has been labeled as dormant by an automated system for having no activity in the last 60 days. Please consider one the following actions: 1️⃣ Close as Out of Date: If the topic is no longer relevant, close the Discussion as 2️⃣ Provide More Information: Share additional details or context — or let the community know if you've found a solution on your own. 3️⃣ Mark a Reply as Answer: If your question has been answered by a reply, mark the most helpful reply as the solution. Note: This dormant notification will only apply to Discussions with the Thank you for helping bring this Discussion to a resolution! 💬 |
|
Is there any way this can be changed? It seems silly that we must accept whatever permissions are requested by a service just to use their app. There's no middle ground. I cannot say "I will use this service, but you cannot have x permission that you want." For instance, Cloudflare does not need "Read and write access to Administration". That's excessive reach and should not be required for users looking to connect the two for automatic deployments. All they need is their original "Read access to code and metadata" and "Read and write access to checks, deployments, and pull requests". If I install an app before the permission is requested, and they later request it be changed, I can simply ignore it and continue to use it as-is. If their app ends up throwing errors as a result, that's on them to work around. We shouldn't be stuck forced to accept all or never use. Why are we not practicing and encouraging the principle of least privilege here? This is a huge miss in security. |
|
You are not doing anything wrong what you are seeing is the intended behavior of GitHub Apps, which treat permissions and scopes fundamentally differently than legacy OAuth Apps. Why the scope Parameter Is Ignored Why the Authorization Screen Always Shows the Same Permissions The permissions you are seeing are the fixed defaults for user-level authorization:
|
Uh oh!
There was an error while loading. Please reload this page.
Select Topic Area
Question
Body
I'm having trouble understanding the permission system when authorizing Github Apps (not OAuth Apps). I understand we can modify the permissions of our apps globally in their settings. These permissions, however, seem to only apply to installations of our apps.
Yet, I can retrieve an OAuth token via the ClientID my app exposes. However, the
scopesfeature does not seem to work for me...Here is an example url:
https://github.com/login/oauth/authorize?response_type=code&client_id=xxx&state=xxx&redirect_uri=http%3A%2F%2Flocalhost%3A5173%2Foauth%2Fgithub%2Fredirect&scope=read%3Auser%20user%3Aemail%20read%3Aproject%20admin%3AorgWhen I check the page for my authorized apps I always see the following permissions:
The authorization screen also looks unchanged in that it always shows
emailas the only requested resource. There is no mention of the extra scopes I requested.What is going on here? Am I doing something wrong?
All reactions