Access posts and comments through my account.
Access the list of subreddits I moderate, contribute to, and subscribe to.
Access my inbox and send private messages to other users.
Access my reddit username and signup date.
Submit links and comments from my account.
Maintain this access indefinitely (or until manually revoked).
I would expect this app to only need 2nd and 4th items in this list.I think I could make a separate application with less permissions and then just this one when two-way communication is ready and opt-in?
Furthermore, again, to the best of my knowledge, if an alien.top user changed their mind and wanted to opt-in to the bidirectional behavior later, you could have that user just re authorize with the same client-id and this time ask for all the scopes. Much less complexity than managing two separate app registrations
Regarding why I'm asking everything upfront, I will (partially) blame the library I'm using to authenticate with reddit, django-allauth. It can be made to make user configurable scope requests, but the default adapter just takes a fixed list of scopes from the overall application setting.
I do understand that it would be better if I asked for the proper permissions on demand, but to be honest it was now just a matter of prioritizing new features over addressing valid-but-minor objections that people might have.
Yeah that's a quick no from me.
I would guess the short version would be "run your own copy with sane scopes" but that would require that I visit reddit again, sign up for their new developer-hating experience, and I just don't care about their content that much
Also, think a bit from my perspective: every user that signs up to my instance but is not willing to have two-way communication is reducing its viral aspect and is costing me resources. I'm not saying that what you want is unreasonable, I'm just saying that there are others that could be more helpful.
If you don't trust me or the application, it's another story. But please don't deride my work as malicious or ignorant of actual security practices.
What has trust got to do with anything once I have observed the wrong thing happening?
Not "instead" but "in addition to". And the reason it is requesting permission to post is separate from "checking the subreddits", it is (like I said) because there are already people who asked for the ability to respond to a comment on reddit from a lemmy thread, and I (admittedly) didn't bother (yet) to write two oauth flows for these two separate actions when one is faster to implement and easier for people to understand.
> I have observed the wrong thing happening?
Have you seen or heard anyone complaining about the application sending posts when it shouldn't? If not, there is nothing objectively wrong with it.
You might be concerned about potential issues with this approach and I completely agree that it is not ideal, but between spending time to (a) write a whole new OAuth adapter class to handle the different requests or (b) creating 15 new different lemmy instances and mapping 175 subreddits to Lemmy communities - which one do you think is more helpful to the goals of the project?
Look, you've already agreed that "it would be better if [you] asked for the proper permissions on demand", and that it was "a matter of prioritizing". Now you are trying to object and call it "deriding" if I don't pretend that you are following security best practices. You are not, you have explained why, what is this thread about?
> what is this thread about?
It really rubs me the wrong way that you are passing opinion as fact, especially when it is an open source project that is meant to help people. Instead of shitting on other people's work by writing things like "I am happy to pass", perhaps go take a look to see how you could make the improvement that is so important to you?
Yes...
> perhaps go take a look to see how you could make the improvement that is so important to you?
No amount of contribution on my part can change your attitude towards security. If it is not a priority of the maintainer, the only move is to stay away.
I'm not saying you are creating a collection of spam accounts, I don't even think it's likely that you are. But if someone wanted to do it, this is exactly the way they should go about it. The only move you could take to prove otherwise (not that you owe it to anyone) is to not request posting permission until you need it, with written explanation.
There is another move: submit a PRs with the change. I would gladly accept it.
Now that this is online for 3 days, I can give you some numbers: 11 people rejected the request and 135 accepted it. If I went by your preferred route, I would have zero rejections and zero conversions, because I would still be struggling with a self-imposed technical requirement.
My time and resources that can be dedicated to this are finite. It doesn't mean that I deny things could be improved, it doesn't mean I won't get to keep working to improve the existing product and it doesn't mean I won't address those concerns later. It just means that this is not meant to be some research project where I need to be satisfying some panel of theoretical experts who never care about the real practice. Right now, the majority of people are telling me "make it easier to find more communities on Lemmy and make it easier to convert more people even if that requires me trusting you", not "I don't trust you enough to let you send messages on my behalf."
That does NOT fix your SECURITY POSTURE. If security is not a priority, you will keep taking shortcuts. You might even have similar issues in your deployment. Sending patches over and over to a software under active development, to try to add something the maintainer doesn't care about, is just not a winning proposition.
> 11 people rejected the request and 135 accepted it
I myself didn't click "decline", I just closed the tab. How many people closed the tab when they reached the Reddit sign-in page? How could you possibly measure whether it's because they didn't agree to the scopes, whether they lost interest, or whether they forgot their Reddit password?
As with any other engineering discipline, it is about trade-offs. If you want to maximize "is it secure?" over "can it be used by people safely?", fine. But at the end of the day I managed to have this delivered and used by hundreds of people, who are now able to go on to tell others about it, and no actual security incident.
> How many people closed the tab?
How people got dropped by the funnel matters little to me compared to the fact that there is a funnel in the first place.
This is not a research project and no one is paying me to optimize this funnel. This is me building a tool to have a migration path out of reddit. Prioritizing having it available to people and other instance owners beats delaying it for a week on the basis of "some people will walk away because they object to the access request."
Those like you can wait for another week, or they can go fork the code if they want, or they can even ignore the whole project and join lemmy directly. But the product is not for "those like you", so why should I be focusing on addressing your concerns over implementing the things that have been actually requested by other people?