Hacker News new | ask | show | jobs
by whatl3y 3040 days ago
I realize this can be a little bit (sometimes more than a little bit) of a development overhead to manage, but isn't the right way to do this is to only require the minimum oauth scopes upon signing up, then add additional scopes and re-auth at the time it's needed (i.e. when someone wants to perform an import)?