# Registrator's crazy privileges

**URL:** <https://discourse.julialang.org/t/registrators-crazy-privileges/52222>\
**Category:** General Usage\
**Tags:** general-registry\
**Created:** [December 22, 2020, 10:35am UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222 "2020-12-22T10:35:56Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![FedericoStra](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@FedericoStra](https://discourse.julialang.org/u/FedericoStra)\
**Post date:** [December 22, 2020, 10:35am UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/1 "2020-12-22T10:35:57Z")

</div>

I was trying to register a package on [https://juliahub.com/ui/Registrator](https://juliahub.com/ui/Registrator) but got stuck at a scary banner:

> We need **read/write privileges for your repositories** to determine whether you are a contributor of this package.

If you click “Grant privileges”, GitHub kindly informs you that

> JuliaHub is requesting additional permissions.  
> This application will be able to **read your notifications** (no code access).  
> This application will be able to **read and write all public repository data**. This includes the following:
> 
> - Code
> - Issues
> - Pull requests
> - Wikis
> - Settings
> - Webhooks and services
> - Deploy keys

To me, this is complete and utter nonsense. It’s as if to register my phone number in the phone book I had to give to the phone company free access to my house and the right to drive my car whenever they please.

And all these privileges are just to _“determine whether you are a contributor of this package”_? Really?

I logged in on JuliaHub using my GitHub credentials, how come they are not sufficient to verify that my account is the owner ot the package I’m trying to register?

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 22, 2020, 11:36am UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/2 "2020-12-22T11:36:48Z")

</div>

Try using the Registrator.jl GitHub App (also called the “comment bot”), which you can install here: [Sign in to GitHub · GitHub](https://github.com/apps/juliateam-registrator/installations/new)

The GitHub App does not require any write permissions. It only requires some read permissions. Here are the permissions that the GitHub App needs:

 ![image](https://global.discourse-cdn.com/julialang/original/3X/3/3/33268d8009d2ebc1ba3762ecfe518bbc2a9a2ef1.jpeg)

More details here: [GitHub - JuliaRegistries/Registrator.jl: Julia package registration bot](https://github.com/JuliaRegistries/Registrator.jl)

In particular, see the “Via the GitHub App” section of the README: [https://github.com/JuliaRegistries/Registrator.jl/blob/master/README.md#via-the-github-app](https://github.com/JuliaRegistries/Registrator.jl/blob/master/README.md#via-the-github-app)

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 22, 2020, 11:41am UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/3 "2020-12-22T11:41:20Z")

</div>

> [@FedericoStra](#):
>
> And all these privileges are just to _“determine whether you are a contributor of this package”_ ? Really?

Just so that you are aware, this is not JuliaHub’s fault. It is due to a limitation in the GitHub API. In order to use the GitHub API to list all collaborators of a repository, you need write access to that repository.

---

<div class="post-metadata">

**Author:** ![oxinabox](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/oxinabox/32/206603_2.png) [@oxinabox](https://discourse.julialang.org/u/oxinabox)\
**Post date:** [December 22, 2020, 2:46pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/4 "2020-12-22T14:46:47Z")

</div>

> [@dilumaluthge](#):
>
> Just so that you are aware, this is not JuliaHub’s fault. It is due to a limitation in the GitHub API. In order to use the GitHub API to list all collaborators of a repository, you need write access to that repository.

It’s really annoying too.  
Do we have something tracked anywhere with GitHub to try and get them to change that, or add another permission type for it?

e.g. it makes it impossibly to grant someone permissions to register just 1 package within an org;  
or to grant them permissions to register releases on a project on your personal account.  
(e.g. for years pre-1.0 Malmaud and I were co-maintaining TensorFlow.jl which lived on Malmauds account. In 1.0 land, I would not be able to register releases AFAIK)

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 22, 2020, 2:48pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/5 "2020-12-22T14:48:22Z")

</div>

> [@oxinabox](#):
>
> e.g. for years pre-1.0 Malmaud and I were co-maintaining TensorFlow.jl which lived on Malmauds account. In 1.0 land, I would not be able to register releases AFAIK)

You should still be able to do this with the GitHub App (“comment bot”).

E.g. Gaius.jl is owned by Mason’s personal account, but I just registered a new version of Gaius using the comment bot.

---

<div class="post-metadata">

**Author:** ![oxinabox](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/oxinabox/32/206603_2.png) [@oxinabox](https://discourse.julialang.org/u/oxinabox)\
**Post date:** [December 22, 2020, 2:50pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/6 "2020-12-22T14:50:43Z")

</div>

How does that work?  
When for GitHub orgs I need to be a public member?

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 22, 2020, 2:53pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/7 "2020-12-22T14:53:26Z")

</div>

It should still work for orgs.

Consider for example PkgTemplates.jl, which is owned by the Invenia org. As far as I am aware, @christopher-dG is not currently a member of the Invenia GitHub org, but he is still able to register new versions of PkgTemplates.jl.

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 22, 2020, 2:55pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/8 "2020-12-22T14:55:17Z")

</div>

If we really want, we could just bypass the GitHub API, and have a feature like this:

Create a file named `registrator-authorized-users.txt` in the root of your package (i.e. in the same directory as your package’s `Project.toml` file) with contents as such:

```julia
@DilumAluthge
@oxinabox

```

And those are the users allowed to register.

---

<div class="post-metadata">

**Author:** ![oxinabox](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/oxinabox/32/206603_2.png) [@oxinabox](https://discourse.julialang.org/u/oxinabox)\
**Post date:** [December 22, 2020, 2:55pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/9 "2020-12-22T14:55:30Z")

</div>

> [@dilumaluthge](#):
>
> Consider for example PkgTemplates.jl, which is owned by the Invenia org. As far as I am aware, @christopher-dG is not currently a member of the Invenia GitHub org, but he is still able to register new versions of PkgTemplates.jl.

Is he? that was actually the exact situation I was worried about.

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 22, 2020, 2:56pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/10 "2020-12-22T14:56:20Z")

</div>

I think he is. The question is: does he use the GitHub App comment bot (no write permissions needed) or the JuliaHub website (write permissions needed).

@christopher-dG

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 22, 2020, 3:11pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/11 "2020-12-22T15:11:56Z")

</div>

The issue might be: what is the source of the user’s write access?

The comment bot works as follows: when someone makes a comment, the bot receives a webhook payload ([Webhook events and payloads - GitHub Docs](https://docs.github.com/en/free-pro-team@latest/developers/webhooks-and-events/webhook-events-and-payloads#issue_comment)). The payload includes the text contents of the comment and the user’s username. The payload also includes an `AUTHOR_ASSOCIATION` Field.

Now this is where things get tricky. If the user has write access because they are the repo owner (user owned repo case) or because they were manually added as an outside collaborator with write access (org owner repo case), then then the `AUTHOR_ASSOCIATION` field will reflect this, and the comment bot knows you have permission to register.

BUT, if you have write access only as a result of being a member of the organization (I.e. all members of the org have write access to this repo; you weren’t specifically added to this repo), then if I understand correctly, the `AUTHOR_ASSOCIATION` will NOT reflect your write access. In this case, the comment bot thinks you don’t have write access. So the comment bot is forced to check if you are an org member, and it uses the GitHub API to do so. Since the comment bot only has read access, it only has permission to access the public members of the org.

Anyway, this is all a little off-topic to the original post. The OP wants to register a package in a repo that is owned by their personal username, and they don’t want to give anyone write access to their repo. They can accomplish this by installing the GitHub App (“comment bot”) as described in my post above.

Can a Discourse admin (@vchuravy @mbauman) split this tangent discussion into a separate Discourse thread?

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [December 30, 2020, 6:53pm UTC](https://discourse.julialang.org/t/registrators-crazy-privileges/52222/12 "2020-12-30T18:53:30Z")

</div>

Sorry, haven’t checked Discourse for some time.

I’m not a member of the Invenia org, I’m just a collaborator on PkgTemplates.jl. I use the comment bot generally.
