[go: up one dir, main page]

Skip to content

Reevaluate permissions needed by Gitpod app

Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.

Description

Currently, it looks like the Gitpod app requires access to the full user API which seems excessive 🤔

Screen_Shot_2020-09-30_at_2.07.43_PM

This opens up a security attack vector for compromising users and could even be a deterrent for user adoption. Let's evaluate what permissions are actually needed by Gitpod. Maybe GitLab needs to expose some permissions in a more granular way?

Edited by 🤖 GitLab Bot 🤖