Appcenter: Don't require the GitHub Bug Tracker user to have admin permissions

Created on 12 Feb 2019  路  8Comments  路  Source: microsoft/appcenter

What App Center service does this affect?
Bug Tracker.

Describe the bug
Currently, the Bug Tracker GitHub user must have admin permissions to any repository you wish to link to. It shouldn't, as I don't want to grant our automation and CI GitHub user account admin permissions.

Expected behavior
I can use a non-administrative GitHub user for our AppCenter Bug Tracker integration.

Desktop (please complete the following information):

  • OS: macOS 10.14.3
  • Browser: Safari
  • Version: 12.0.3 (14606.4.5)
bug

All 8 comments

Hey @tonyarnold ! Thanks for giving us this feedback. We designed the bug tracker integration to require admin permissions for security/privacy reasons. Could you share more about your use case?

Also, if anyone else faces this issue, please give a 馃憤 to Tony's comment.

Hi @amchew - I don't have the information that led your team to design the feature to require admin permissions, but that seems really odd to me.

Shouldn't you be aiming to ask for the minimum required permissions to prevent any misuse of the integration? I don't want to have administrative accounts lying around unnecessarily, and this seems totally unnecessary given that all the integration does is read and file new issues as they occur in AppCenter.

Hi @tonyarnold , thanks for the feedback, we do appreciate it. We're discussing this behavior internally, and will get back to you shortly. Will reply to this thread again.

Hi @tonyarnold, we hear your feedback, and have recorded this down in our backlog. We unfortunately don鈥檛 have an ETA to fix this. I know this may not be the answer you want to hear.

I鈥檒l leave this bug open, and if anyone else if facing this issue, please give a thumbs up. We continually reprioritize our backlog based on your feedback.

Excellent! Thanks for the solid communication and transparency. I understand that you don't have an ETA, but at least it's being tracked now. Thanks again!

No problem! :)

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 7 days if no further requests are made to keep it open.

Can someone un-invite stalebot? It's a seriously poor look for issues that haven't seen any work yet to be closed by an automated service.

Was this page helpful?
0 / 5 - 0 ratings