Affected Area
None
Problem Statement
When storing GitHub access token of a user in the team document, the token is accessible to all members of the team, and so are all the private repositories accessible to the token.
Proposed Solution
There should be better scoping in terms of who is allowed to have whitelisted access to a given repository.
ref: https://support.frappe.io/helpdesk/tickets/74797
Affected Area
None
Problem Statement
When storing GitHub access token of a user in the team document, the token is accessible to all members of the team, and so are all the private repositories accessible to the token.
Proposed Solution
There should be better scoping in terms of who is allowed to have whitelisted access to a given repository.
ref: https://support.frappe.io/helpdesk/tickets/74797