-
New Feature
-
Resolution: Fixed
-
Critical
-
None
The current default behavior is to request these scopes from GH:
repo,read:org
The repo scope is very broad and grants read/write permissions to public and private repos across all organizations to which the user is a member. This is a "deal breaker" for some of my end users and unnecessary since the relevant repos are all public. We need a mechanism to configure / reduce the requested scope(s).
- is related to
-
JENKINS-23324 GitHub OAuth 0.17 requires private access to all repositories
- Resolved
-
JENKINS-26145 Narrow down github auth scope for user logins
- Resolved
-
JENKINS-20845 Private user memberships can't be used for authorization
- Resolved
-
JENKINS-26789 Upcoming GitHub API changes
- Resolved