Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

revoking app authorizations #24

Closed
elf-pavlik opened this issue Aug 28, 2019 · 2 comments
Closed

revoking app authorizations #24

elf-pavlik opened this issue Aug 28, 2019 · 2 comments

Comments

@elf-pavlik
Copy link
Member

elf-pavlik commented Aug 28, 2019

I haven't seen yet conversations about revoking authorizations person grants for specific app. I think we should consider full flow which includes both granting, expanding grants as needed, making them more restrictive as needed and revoking all together.
Having app authorizations scattered across lots of different resource servers would require that person has at least some index where all those authorizations get tracked. Otherwise I don't see clear way to manage them so also revoke them.
I'll think of some use cases that include revoking app authorizations.

@zenomt
Copy link
Contributor

zenomt commented Oct 20, 2019

the scheme described in #48 stores the user's app authorization choices in the user's storage, and would allow the user to audit, modify, and remove app authorizations.

@elf-pavlik
Copy link
Member Author

https://solid.github.io/data-interoperability-panel/specification/#authorizations provides End-user centric approach which addresses this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants