[PR #6171] [MERGED] [BRE-1333] Added permissions to token generation step to limit token scope #32386

Closed
opened 2026-04-18 15:46:52 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/bitwarden/android/pull/6171
Author: @gitclonebrian
Created: 11/14/2025
Status: Merged
Merged: 12/10/2025
Merged by: @gitclonebrian

Base: mainHead: BRE-1333/workflow-token-perms_android1


📝 Commits (2)

  • 18f27a6 added permissions to token generation step to limit token scope
  • 4c299ad added empty permission set at workflow level. removed contents: write and pull-requests: writefrom job. addedcontents: read` to job.

📊 Changes

1 file changed (+5 additions, -2 deletions)

View changed files

📝 .github/workflows/crowdin-pull.yml (+5 -2)

📄 Description

🎟️ Tracking

BRE-1333

📔 Objective

Adding permissions to token generation step to limit token scope per least privilege best practice.
Changes were tested:

  • manual workflow run was initiated from this branch
  • translations were downloaded
  • PR was generated here

📸 Screenshots

Reminders before review

  • Contributor guidelines followed
  • All formatters and local linters executed and passed
  • Written new unit and / or integration tests where applicable
  • Protected functional changes with optionality (feature flags)
  • Used internationalization (i18n) for all UI strings
  • CI builds passed
  • Communicated to DevOps any deployment requirements
  • Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team

🦮 Reviewer guidelines

  • 👍 (:+1:) or similar for great changes
  • 📝 (:memo:) or ℹ️ (:information_source:) for notes or general info
  • (:question:) for questions
  • 🤔 (:thinking:) or 💭 (:thought_balloon:) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion
  • 🎨 (:art:) for suggestions / improvements
  • (:x:) or ⚠️ (:warning:) for more significant problems or concerns needing attention
  • 🌱 (:seedling:) or ♻️ (:recycle:) for future improvements or indications of technical debt
  • ⛏ (:pick:) for minor or nitpick changes

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/bitwarden/android/pull/6171 **Author:** [@gitclonebrian](https://github.com/gitclonebrian) **Created:** 11/14/2025 **Status:** ✅ Merged **Merged:** 12/10/2025 **Merged by:** [@gitclonebrian](https://github.com/gitclonebrian) **Base:** `main` ← **Head:** `BRE-1333/workflow-token-perms_android1` --- ### 📝 Commits (2) - [`18f27a6`](https://github.com/bitwarden/android/commit/18f27a6c530f54b99e022c42f9d090362c736d22) added permissions to token generation step to limit token scope - [`4c299ad`](https://github.com/bitwarden/android/commit/4c299ad18e16c62aec8737f75910a23683a77732) added empty permission set at workflow level. removed `contents: write` and pull-requests: write` from job. added `contents: read` to job. ### 📊 Changes **1 file changed** (+5 additions, -2 deletions) <details> <summary>View changed files</summary> 📝 `.github/workflows/crowdin-pull.yml` (+5 -2) </details> ### 📄 Description ## 🎟️ Tracking [BRE-1333](https://bitwarden.atlassian.net/browse/BRE-1333) ## 📔 Objective Adding permissions to token generation step to limit token scope per least privilege best practice. Changes were tested: - manual workflow run was initiated from this branch - translations were downloaded - PR was generated [here](https://github.com/bitwarden/android/pull/6170) ## 📸 Screenshots <!-- Required for any UI changes; delete if not applicable. Use fixed width images for better display. --> ## ⏰ Reminders before review - Contributor guidelines followed - All formatters and local linters executed and passed - Written new unit and / or integration tests where applicable - Protected functional changes with optionality (feature flags) - Used internationalization (i18n) for all UI strings - CI builds passed - Communicated to DevOps any deployment requirements - Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team ## 🦮 Reviewer guidelines <!-- Suggested interactions but feel free to use (or not) as you desire! --> - 👍 (`:+1:`) or similar for great changes - 📝 (`:memo:`) or ℹ️ (`:information_source:`) for notes or general info - ❓ (`:question:`) for questions - 🤔 (`:thinking:`) or 💭 (`:thought_balloon:`) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion - 🎨 (`:art:`) for suggestions / improvements - ❌ (`:x:`) or ⚠️ (`:warning:`) for more significant problems or concerns needing attention - 🌱 (`:seedling:`) or ♻️ (`:recycle:`) for future improvements or indications of technical debt - ⛏ (`:pick:`) for minor or nitpick changes [BRE-1333]: https://bitwarden.atlassian.net/browse/BRE-1333?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-04-18 15:46:52 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#32386