diff --git a/app/pages/connect.vue b/app/pages/connect.vue index c762d85..79c9a84 100644 --- a/app/pages/connect.vue +++ b/app/pages/connect.vue @@ -51,6 +51,13 @@ const accountLabel = login ?? 'your GitHub account' then you'll pick the tangled handle that mirrors it. we check this so nobody else can bind your repositories to their identity.

+

+ GitHub's next screen always lists “act on your behalf” for any + app you authorize. synchub asks for no account permissions at all: we + make one request, for the list of installations you administer, to + check {{ accountLabel }} is one of them. the token is + discarded straight afterwards and never stored. +

verify with GitHub @@ -146,6 +153,15 @@ const accountLabel = login ?? 'your GitHub account' margin: 0 0 var(--space-lg); } +.connect__note { + max-width: var(--measure); + margin: 0 0 var(--space-lg); + padding-left: var(--space-md); + border-left: var(--rule-hair) solid var(--color-rule); + color: var(--color-neutral); + font-size: var(--text-sm); +} + .signin { display: flex; flex-wrap: wrap;