Create more granular accounting scopes (eg: Sales - Invoice only)
Right now there is a very wide range of APIs wrapped up in the "accounting.transactions" scope, with no way to provide more granular access within these APIs (https://developer.xero.com/documentation/guides/oauth2/scopes#organisation-scopes).
This means that it's not possible to grant access to something quite narrow without also granting access to other things that are often not needed. For example, you cannot grant permission to creating/manipulating Sales Invoices without also giving access to all Bank Transactions at the same time.
This problem is perhaps accentuated for Custom Connections, which are designed to be used for "in house" integrations, as ALL developers with access to maintain such a sales invoice integration would effectively have access to their colleague's salaries and company bank balances and nothing can be done to mitigate against this.
It feels like either there should be an extra layer of scopes such as "accounting.transactions.invoice" or "accounting.transactions.sales" available.
I would also think this is quite easy to implement!
You can now request smaller, more specific scopes instead of the broad accounting.transactions and accounting.reports.read scopes. This gives you more control over what your app can access, and gives your users a clearer picture of what they're approving when they connect your app. See the OAuth 2.0 scopes documentation for the full list of scopes, and the Granular scopes FAQ for more.
accounting.journals.read is no longer granted by default.
To access journals, you'll need the Advanced tier and certification.
https://developer.xero.com/changelog#new-granular-scope-for-the-accounting-api
-
Gavin Harris commented
Projects is just as bad! Like Time Entries should be something that is able to be made available to employees, however to allow an employee to have access to enter their Time they also also need to be granted full access to Projects, Tasks and Time Entries!
-
Cesar Ho commented
Although there is upgraded scope (https://developer.xero.com/documentation/guides/oauth2/scopes/), however, accounting.invoices still can read both invoices and bills, which will expose the bills to the team who handle 'sales -invoice only'.
Suggest to spilt invoices vs bills scope.
-
James Garner commented
More fine grained scopes would be highly appreciated.
We are building an important internal integration to extract approved leave.
It seems silly (and a high PII exposure risk) that the scope that allows access to LeaveApplications also allows you to access employee's PII and banking details.
-
Trent Bagshaw commented
In order to provide access to Quotes I have to give access to wage related Bank Transactions. This is... silly? Unless I'm missing something
-
Y V commented
Please implement this feature
-
Noach Vogel commented
Please implement this important feature
-
M Gansburg commented
Please implement asap
-
Tobie Vogel commented
This is critical. Please implement ASAP
-
Mendy Jacobs commented
This is very important to us, can you please implement,
-
Yosef vogel commented
Please implement this.
-
MV commented
This is critical please implement this especially for invoices.
-
HC
commented
It is a significant issue for us that we can't grant some users access to create/see invoices only via the API. Our users are effectively over permissioned and we have to ask them not to look at sensitive information (such as account reconciliations). It's not a nice state to exist in.