Skip to content

Investigate how can make pages auth work with only `read_api` scope

From https://gitlab.com/gitlab-org/security/gitlab-pages/-/merge_requests/6#note_464150499:

Taking a step back here and I wanted to ask why do we need api scope for the token?

That's a good question, we should be fine with the read_api scope at least.

Edited by Vasilii Iakliushin