Skip to content

Conversation

@100xff
Copy link
Contributor

@100xff 100xff commented Feb 13, 2025

The acl scope is listed as a "legacy scope" and the replacement is the policy_file scope. But, as per the documentation, this additionally requires devices:core:read and devices:posture_attributes.

The acl scope is listed as a "legacy scope" and the replacement is the
policy_file scope. But, as per the documentation, this additionally
requires devices:core:read and devices:posture_attributes.

See: https://tailscale.com/kb/1215/oauth-clients#scopes
See: https://tailscale.com/kb/1215/oauth-clients#legacy-scopes
@100xff
Copy link
Contributor Author

100xff commented Feb 13, 2025

I'm not sure why we need devices:posture_attributes (i.e. the write permission) for this, or even why we need to read devices at all, but it's how it is documented.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant