brianpgerson / callie

It's a countdown bot for Slack
27 stars 8 forks source link

Privacy concern regarding Callie's permissions #8

Closed kureus closed 6 years ago

kureus commented 6 years ago

On looking to install Callie, Slack presents two warnings

Add a bot user with the username @callie
Callie will be able to install a bot user that appears in and has access to your workspace’s directory. It can also post messages and view activity on messages in any channel it is invited to.

Access content in your public channels
Callie will be able to access any messages and activity you can see in public channels.

The first is understandable, the second however I cannot see an obvious need for? Why would Callie need to be able to access content in all public channels?

brianpgerson commented 6 years ago

Hello there Dan -

That is how Callie is able to respond to messages! If we couldn’t see em, we couldn’t respond to them.

That said, we don’t save or persist messages anywhere so it shouldn’t be a concern.

Anyways, hope that answers your question.

On Sat, May 26, 2018 at 6:16 AM Dan Quirk notifications@github.com wrote:

On looking to install Callie, Slack presents two warnings

Add a bot user with the username @callie Callie will be able to install a bot user that appears in and has access to your workspace’s directory. It can also post messages and view activity on messages in any channel it is invited to.

Access content in your public channels Callie will be able to access any messages and activity you can see in public channels.

The first is understandable, the second however I cannot see an obvious need for? Why would Callie need to be able to access content in all public channels?

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/brianpgerson/the-count/issues/8, or mute the thread https://github.com/notifications/unsubscribe-auth/ALEO6JoW4GgO9jmhJUXsYGKiOgAEwSwNks5t2VXCgaJpZM4UO6XC .

--

Brian Gerson LinkedIn https://www.linkedin.com/in/brianpgerson Github http://github.com/brianpgerson