fix: remove private repository scope from github oauth#1095
Open
Niteshagarwal01 wants to merge 2 commits into
Open
fix: remove private repository scope from github oauth#1095Niteshagarwal01 wants to merge 2 commits into
Niteshagarwal01 wants to merge 2 commits into
Conversation
|
@Niteshagarwal01 is attempting to deploy a commit to the PRIYANSHU DOSHI's projects Team on Vercel. A member of the Team first needs to authorize it. |
GSSoC Label Checklist 🏷️@Priyanshu-byte-coder — please apply the appropriate labels before merging: Difficulty (pick one):
Quality (optional):
Validation (required to score):
|
There was a problem hiding this comment.
Thanks for your first PR on DevTrack! 🎉
A maintainer will review it within 48 hours. While you wait:
- Make sure CI is passing (type-check + lint)
- Double-check the PR description is filled out and the issue is linked
- Feel free to ask questions in Discussions if you need help
If you find DevTrack useful, a ⭐ star on the repo is always appreciated — it helps the project grow and attract more contributors!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR removes the unnecessary
reposcope from the GitHub OAuth flow to prevent requesting access to users' private repositories. This addresses user privacy concerns, adheres to the principle of least privilege, and ensures the application only requests the minimum essential scopes (read:user,user:email,read:discussion) required for authentication and basic profile info.(Note: I worked on this PR as the associated issue was assigned to me under GSSoC 2026.)
Closes #1088
Type of Change
Changes Made
src/lib/auth.ts: Removed thereposcope from theGitHubProviderauthorization parameters.src/app/api/auth/link-github/route.ts: Removed thereposcope from the URL search parameters when a user links their GitHub account.How to Test
Steps for the reviewer to verify this works:
Screenshots (if UI change)
N/A - This is an OAuth permission scope change.
Checklist
npm run lintpasses locallynpm run type-check)You can just copy and paste this into GitHub when you open your PR!