Current problem
the "identity" scope desccription when authorizing an app says it can access "username, avatar, etc.":
pasted-image-1.png
IMO using "etc" here isn't a good idea. for something like this, the user should be told exactly what the app can and can't access. my first thought when i read this was "can it see my email address?" i have no idea. or is it just public profile information?
Proposed change
clarify everything that the app can access from this scope in the message. eg:
Access your basic profile information (username, display name, avatar, banner)

Comments
No comments yet.