indieweb / indieweb/wordpress-indieauth
Don't issue tokens if user has no permission
Open
- Dominant language
- PHP
- Stars
- 36
- Forks
- 14
- Avg merge
- 2h 6m
- Merged PRs (30d)
- 3
Description
As part of taking more scope control into the IndieAuth plugin, it shouldn't issue scopes the user cannot support
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by tracing token issuance and the IndieAuth plugin's scope-control and permission handling. The work is done when the plugin no longer issues scopes that the user cannot support, but the issue does not name a file or test to run.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php, wordpress
- Domain
- authorization
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100