Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stop using github auth and switch to oauth #3827

Open
greggman opened this issue Dec 20, 2024 · 1 comment
Open

Stop using github auth and switch to oauth #3827

greggman opened this issue Dec 20, 2024 · 1 comment

Comments

@greggman
Copy link

I'm sure this will fall on deaf ears but whatever, I'm reporting it.

No developer that cares about security should ever be using github auth which asks for the most ridiculous permissions ever

Screenshot 2024-12-20 at 10 32 42

No, you do not have permission to act on my behalf and this site should not need that permission. If you clicked to allow it you're effectively giving this site permission to hack all of your repos. I know that's not actually what happens but nothing about the wording makes that clear and so following the wording you are giving permission to edit all of your repos which is insanely not security conscious.

Please stop using github auth or at least provide other means to report issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants