fregante/github-issue-link-status

personal access token should only use public_repo scope by default

Aperta

#67 aperta il 3 nov 2021

 (1 commento) (0 reazioni) (0 assegnatari)JavaScript (22 fork)github user discovery
enhancementhelp wanted

Metriche repository

Star
 (310 stelle)
Metriche merge PR
 (Nessuna PR mergiata in 30 g)

Descrizione

Thanks for such a nice project!


From the security perspective, I think it had better to check only public_repo access by default when we click the Generate One link.

I in this case, we can replace the following link:

- https://github.com/settings/tokens/new?scopes=repo&description=GitHub%20Issue%20Link%20Status
+ https://github.com/settings/tokens/new?scopes=public_repo&description=GitHub%20Issue%20Link%20Status

Also, It's worth to mention if someone wants to use this extension in the private repositories, we can mention that by saying something like: "To use this extension in the private repositories, consider give repo scope to use."

Wdyt?

Screen Shot 2021-11-03 at 22 03 31

Screen Shot 2021-11-03 at 22 03 59

Guida contributor