<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scope hidding in Spotify for Developers</title>
    <link>https://community.spotify.com/t5/Spotify-for-Developers/Scope-hidding/m-p/5582798#M9260</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Device&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Windows 10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Operating System&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(iOS 10, Android&amp;nbsp;Oreo, Windows 10,etc.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Question or Issue&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I was doing&amp;nbsp;some tests with spotify api, and I've found a way to hide the scopes a user allows an application to use when you access&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://accounts.spotify.com/authorize" target="_blank" rel="noopener"&gt;accounts.spotify.com/authorize&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to get the tokens. For example, an application can ask to be able to see the user's public information, but at the end, the application gets a token to see the user's private information.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In the pictures attached, we see that the application is asking for being able to modify playlist.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.spotify.com/t5/image/serverpage/image-id/157587i79AAA994F68E20C6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;But, in reality I asked for :&lt;UL class=""&gt;&lt;LI&gt;&lt;A class="" href="https://developer.spotify.com/documentation/web-api/concepts/scopes#user-read-email" target="_blank" rel="noopener"&gt;user-read-email&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A class="" href="https://developer.spotify.com/documentation/web-api/concepts/scopes#user-read-private" target="_blank" rel="noopener"&gt;user-read-private&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And so I get (I've hidden the tokens) :&lt;/P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.spotify.com/t5/image/serverpage/image-id/157589iB005C51DE3656278/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;even if the &lt;A href="https://accounts.spotify.com/" target="_blank" rel="noopener"&gt;https://accounts.spotify.com/&lt;/A&gt;authorize&amp;nbsp;was not showing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;I don't know if this is already known or&amp;nbsp;if it&amp;nbsp;is not important, but if not you can contact me back, so I could explain to you the technical details.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Best regards.&lt;/DIV&gt;</description>
    <pubDate>Wed, 17 May 2023 22:39:27 GMT</pubDate>
    <dc:creator>thascoet</dc:creator>
    <dc:date>2023-05-17T22:39:27Z</dc:date>
    <item>
      <title>Scope hidding</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/Scope-hidding/m-p/5582798#M9260</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Device&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Windows 10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Operating System&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(iOS 10, Android&amp;nbsp;Oreo, Windows 10,etc.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Question or Issue&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I was doing&amp;nbsp;some tests with spotify api, and I've found a way to hide the scopes a user allows an application to use when you access&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://accounts.spotify.com/authorize" target="_blank" rel="noopener"&gt;accounts.spotify.com/authorize&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to get the tokens. For example, an application can ask to be able to see the user's public information, but at the end, the application gets a token to see the user's private information.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In the pictures attached, we see that the application is asking for being able to modify playlist.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.spotify.com/t5/image/serverpage/image-id/157587i79AAA994F68E20C6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;But, in reality I asked for :&lt;UL class=""&gt;&lt;LI&gt;&lt;A class="" href="https://developer.spotify.com/documentation/web-api/concepts/scopes#user-read-email" target="_blank" rel="noopener"&gt;user-read-email&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A class="" href="https://developer.spotify.com/documentation/web-api/concepts/scopes#user-read-private" target="_blank" rel="noopener"&gt;user-read-private&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And so I get (I've hidden the tokens) :&lt;/P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.spotify.com/t5/image/serverpage/image-id/157589iB005C51DE3656278/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;even if the &lt;A href="https://accounts.spotify.com/" target="_blank" rel="noopener"&gt;https://accounts.spotify.com/&lt;/A&gt;authorize&amp;nbsp;was not showing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;I don't know if this is already known or&amp;nbsp;if it&amp;nbsp;is not important, but if not you can contact me back, so I could explain to you the technical details.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Best regards.&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 May 2023 22:39:27 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/Scope-hidding/m-p/5582798#M9260</guid>
      <dc:creator>thascoet</dc:creator>
      <dc:date>2023-05-17T22:39:27Z</dc:date>
    </item>
  </channel>
</rss>

