thibaultmol@en.osm.town
thibaultmol@en.osm.town

#microblog is pretty cool how it allows you to leave comments by logging into your fedi account and such.... But .... does it really need to have full account permissions?.... I'm not giving it that, sorry)

example of a micro.blog site: taonaw.com/2024/12/11/kagi-ban

The image shows an authorization screen for Micro.blog requesting access to a Mastodon account. The screen has a dark background with white text and includes the following elements:

1. A header stating

|
Embed
Progress spinner
sha@fosstodon.org
sha@fosstodon.org

@thibaultmol Its creator @manton should be able to figure out what’s going on. Thinking about joining myself.

|
Embed
Progress spinner
In reply to
manton
manton

@sha @thibaultmol Good point, it only needs read access to verify the account. I'll change that this week.

|
Embed
Progress spinner
thibaultmol@en.osm.town
thibaultmol@en.osm.town

@manton @sha
Q: is there a way that you could request read access but without having access to my private mentions or is that not possible? (I haven't looked at the documentation)

|
Embed
Progress spinner
thibaultmol@en.osm.town
thibaultmol@en.osm.town

@manton @sha actually, isn't that what
api/v1/accounts/verify_credentials is for?

|
Embed
Progress spinner
manton
manton

@thibaultmol @sha We do call verify_credentials but auth has to happen first. However, there's a "profile" scope that I think will work without actually getting access to posts or DMs. That's what I'm switching to for this case.

|
Embed
Progress spinner