fregante/github-issue-link-status

personal access token should only use public_repo scope by default

Offen

#67 geöffnet am 03.11.2021

 (1 Kommentar) (0 Reaktionen) (0 zugewiesene Personen)JavaScript (22 Forks)github user discovery
enhancementhelp wanted

Repository-Metriken

Stars
 (310 Sterne)
PR-Merge-Metriken
 (Keine gemergten PRs in 30 T)

Beschreibung

Thanks for such a nice project!


From the security perspective, I think it had better to check only public_repo access by default when we click the Generate One link.

I in this case, we can replace the following link:

- https://github.com/settings/tokens/new?scopes=repo&description=GitHub%20Issue%20Link%20Status
+ https://github.com/settings/tokens/new?scopes=public_repo&description=GitHub%20Issue%20Link%20Status

Also, It's worth to mention if someone wants to use this extension in the private repositories, we can mention that by saying something like: "To use this extension in the private repositories, consider give repo scope to use."

Wdyt?

Screen Shot 2021-11-03 at 22 03 31

Screen Shot 2021-11-03 at 22 03 59

Contributor Guide