Downscoped tokens still have too much access

New post



  • jcleblanc



    At the current time the two that will be the most restrictive for your needs would be base_upload (which you're using) and item_upload. With both of those there will still be a number of other endpoints that will be enabled for deeper inspection of the content in the granted folder. Since Box's folder structures are based on a waterfall methodology, that results in what you're seeing - being able to view folder / file content underneath the folder that permissions were granted for. The only other option that I can think of would be to adjust the folder structure of where the content would be uploaded so that the sub folders are not present. I know that's not ideal in many existing cases.


    On the long term side, we are discussing the options for creating more granular level scoping to restrict additional endpoints more easily. These are just discussions / research at the current time, but we do see the need to expand in that direction for more granular control of the access rights of a token.


    - Jon

    Comment actions Permalink
  • rghuron

    Thank you Jon for the quick response. I'll keep an eye out for discussions on the more restrictive scopes.

    Comment actions Permalink

Please sign in to leave a comment.