HNHacker News
TopNewBestAskShowJobs
ParentFull thread
mdaniel·
I would not claim to be a oauth2 expert, but to the best of my knowledge the scopes that one declares during the app registration on the reddit side are the upper bound of what said app is allowed to request, and thus if there was a checkbox on alien.top's side asking whether the user wanted bidirectional behavior, if unchecked the oauth2 handshake would omit the write scopes from the handshake and the token that comes back would be read only. I have mixed feelings about the "offline" part but if it was read only, I would be perfectly fine with alien.top using my access token to help spread the rate limiting load during any sync activities for the subreddits I was in

Furthermore, again, to the best of my knowledge, if an alien.top user changed their mind and wanted to opt-in to the bidirectional behavior later, you could have that user just re authorize with the same client-id and this time ask for all the scopes. Much less complexity than managing two separate app registrations

View on HN
You are correct on almost everything, except on the ability on using your access token to spread rate limiting : requests still depend on the application id, so every request will use the app id quota. This is why the Apollo developer basically said that the pricing changes would kill any chance of having the app financially viable.

Regarding why I'm asking everything upfront, I will (partially) blame the library I'm using to authenticate with reddit, django-allauth. It can be made to make user configurable scope requests, but the default adapter just takes a fixed list of scopes from the overall application setting.

I do understand that it would be better if I asked for the proper permissions on demand, but to be honest it was now just a matter of prioritizing new features over addressing valid-but-minor objections that people might have.

Reply on news.ycombinator.com