<p></p>
<p>Yes if an application doesn't specify any scopes then all scopes are allowed - unfortunately it's not easy to change.</p>
<p>As best I could tell when looking at it yesterday we'd have to override the application model and add an extra validation to it that prevented creating applications with no scopes, which is possible but a bit of a pain so I guess it depends on how important we think it is.</p>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">—<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/openstreetmap/openstreetmap-website/issues/1408#issuecomment-818975146">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/AAK2OLPQ5V2TCTEASECD2Q3TISHAHANCNFSM4C3VTPOA">unsubscribe</a>.<img src="https://github.com/notifications/beacon/AAK2OLJFNY3TFOQSH7EKOQLTISHAHA5CNFSM4C3VTPOKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOGDIJDKQ.gif" height="1" width="1" alt="" /></p>
<script type="application/ld+json">[
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"potentialAction": {
"@type": "ViewAction",
"target": "https://github.com/openstreetmap/openstreetmap-website/issues/1408#issuecomment-818975146",
"url": "https://github.com/openstreetmap/openstreetmap-website/issues/1408#issuecomment-818975146",
"name": "View Issue"
},
"description": "View this Issue on GitHub",
"publisher": {
"@type": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]</script>