I think I could make a separate application with less permissions and then just this one when two-way communication is ready and opt-in?
I think I could make a separate application with less permissions and then just this one when two-way communication is ready and opt-in?
Furthermore, again, to the best of my knowledge, if an alien.top user changed their mind and wanted to opt-in to the bidirectional behavior later, you could have that user just re authorize with the same client-id and this time ask for all the scopes. Much less complexity than managing two separate app registrations
Regarding why I'm asking everything upfront, I will (partially) blame the library I'm using to authenticate with reddit, django-allauth. It can be made to make user configurable scope requests, but the default adapter just takes a fixed list of scopes from the overall application setting.
I do understand that it would be better if I asked for the proper permissions on demand, but to be honest it was now just a matter of prioritizing new features over addressing valid-but-minor objections that people might have.