From 329df9e78e3f4f5c22d66d8609459eb842abc250 Mon Sep 17 00:00:00 2001 From: Aly Raffauf Date: Mon, 13 Jul 2026 14:36:53 -0400 Subject: [PATCH] atproto/auth: replace broad transition:generic scope with granular tangled scopes --- atproto/auth.go | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/atproto/auth.go b/atproto/auth.go index bdf4ccd..4c439ff 100644 --- a/atproto/auth.go +++ b/atproto/auth.go @@ -16,9 +16,25 @@ import ( var ErrNotAuthenticated = errors.New("not authenticated") -// DefaultScopes are requested for a CLI session. transition:generic grants -// broad repository write access equivalent to an app password. -var DefaultScopes = []string{"atproto", "transition:generic"} +// DefaultScopes are requested for a CLI session. Rather than the broad +// transition:generic scope (equivalent to an app password), we request +// granular permissions scoped to all Tangled collections preemptively, +// so future features don't require re-authentication. The rpc scopes are +// needed for the PDS to mint service-auth JWTs for knot procedures. +var DefaultScopes = []string{ + "atproto", + "repo:sh.tangled.actor.profile", + "repo:sh.tangled.feed.comment", + "repo:sh.tangled.feed.star", + "repo:sh.tangled.graph.follow", + "repo:sh.tangled.graph.vouch", + "repo:sh.tangled.publicKey", + "repo:sh.tangled.repo", + "repo:sh.tangled.repo.issue", + "repo:sh.tangled.repo.pull", + "rpc:sh.tangled.repo.create?aud=*", + "rpc:sh.tangled.repo.setDefaultBranch?aud=*", +} type AuthManager struct { App *oauth.ClientApp -- 2.51.2