Replies: 1 comment 3 replies
-
Sorry for the alarming notice, unfortunately that's how GitHub phrases it. They definitely should've done a better job at that. Simply put, it's just so that the app can post comments under your username. For example, if you see the comments in https://github.com/orgs/giscus/discussions/62, most of them have "with giscus" beside the username and timestamp: For more details, see Authorizing GitHub Apps. See also this comment from a GitHub staff: community/community#37117 (comment) The actual permissions required by the app will show up when you install it on a repository, which are literally just:
|
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hey! Really cool app here, and thanks for making it available for anyone to use.
Question about security. When a GitHub user wants to leave a comment via giscus, they must sign in to GitHub and authorize the giscus app to "Act on your behalf". What set of permissions does this give the giscus app? I understand that giscus obviously needs permission to create/edit/delete discussion items for a particular repository. But the wording "Act on your behalf" is vague and it's not clear what authority I'm giving this app. Does giscus have authority to perform any action that my account could otherwise perform? Thanks for clarifying! Looking forward to using this application in the future.
Beta Was this translation helpful? Give feedback.
All reactions