Last modified: 2014-01-24 01:42:17 UTC
Right now, if an OAuth consumer wishes to add or remove grants that their application needs, they have to go through the approvals process again as a separate application. Consumers should have a way to update the grants for their application without having to do essentially create it as a new application.
I just want to note here that if we allow people to update the grants on their OAuth consumer, we'll need to give all users who have approved that consumer on their account a reconfirmation dialogue, so that they're aware that the consumer's granted rights have changed and that it applies to their account.
Can we actually trigger a reconfirmation dialog in that situation, and will client applications know how to handle it? Or would we just revoke the auth token and let the client treat it as a revocation?
When the end user authorizes the consumer, it saves the list of grants that the end user actually authorized. So it *should* work that the consumer would continue to be granted only the old set of permissions until such time as the it sends the end user through the authorization page again and the end user re-authorizes.
(In reply to comment #3) > When the end user authorizes the consumer, it saves the list of grants that > the > end user actually authorized. So it *should* work that the consumer would > continue to be granted only the old set of permissions until such time as the > it sends the end user through the authorization page again and the end user > re-authorizes. On a personal level this is the work flow that I'd like the most but I can certainly see arguments for trying to force it.