Skip to content

Create FR for 1.4.3 - least_privilge_app_permissions

As per: !138 (merged) we talked about 1.4.3 - least_privilge_app_permissions in that we can make a feature request to allow applications to return their permissions in the REST API.

example
>>> pprint(glObject.applications.list()[0].__dict__)
{'_attrs': {'application_id': 'd4e0e07c1e4d25a82d1f6d4a290fe8b3a062c7fd2477a79f7184d483f95a1732',
            'application_name': 'web.site',
            'callback_url': 'https://web.site/callback',
            'confidential': True,
            'id': 2},
...

Versus actually showing the scopes the App has:

Screenshot_2025-02-17_at_5.23.30_PM

This would allow us to start looking at applications that have "critical" scopes, to at least probably FAIL for excessive perms.