Scary warning message when logging in to third party app using account that is Admin via OAuth using read_user scope

Summary

When using the read_user scope for OAuth authentication the authorization page still warns admins that they are granting increased access to gitlab

Steps to reproduce

Configure an application to use GitLab for OAuth2 authenication Log in using an account that is an Admin in GitLab

Expected behavior

You should see a summary of what access you are authorizating.

Actual behavior

You see a warning that

" You are an admin, which means granting access to docker-examples will allow them to interact with GitLab as an admin as well. Proceed with caution."

Possible fixes

Check to see if the permissions being granted actually warrant a warning message for Admins.

Edited Jun 17, 2025 by 🤖 GitLab Bot 🤖
Assignee Loading
Time tracking Loading