Skip to content

Stop using github auth and switch to oauth #3827

Open
@greggman

Description

@greggman

I'm sure this will fall on deaf ears but whatever, I'm reporting it.

No developer that cares about security should ever be using github auth which asks for the most ridiculous permissions ever

Screenshot 2024-12-20 at 10 32 42

No, you do not have permission to act on my behalf and this site should not need that permission. If you clicked to allow it you're effectively giving this site permission to hack all of your repos. I know that's not actually what happens but nothing about the wording makes that clear and so following the wording you are giving permission to edit all of your repos which is insanely not security conscious.

Please stop using github auth or at least provide other means to report issues.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions