tree efc06e659f8de16aa668281e9e44190c321c7b45
parent c305f6afd88d8fac9269759038c88bd170ce9e32
author Luca Milanesio <luca.milanesio@gmail.com> 1386751486 +0000
committer Luca Milanesio <luca.milanesio@gmail.com> 1392154268 +0000

Get user's SSH verified keys only using published info.

Use the GitHub public and unrestricted API for accessing
the user's SSH public keys.
There are a couple of benefits associated to this:
1. Get only the SSH keys that have been verified for 
   that user and made public to all the world.
2. Avoid requesting the "user" scope during OAuth
   which grants unnecessary WRITE access to the user's
   profile.

The latter raised concerns on people in doubt of 
what Gerrit would have done to their GitHub user's
profile because of the involuntary WRITE access
requested before.

Drawbacks: we cannot get anymore the SSH label associated
to the published keys, as GitHub keeps that info
confidential. This is an acceptable price to pay in 
order to lower the concerns on the GitHub OAuth scope. 

NOTE: This commit uses a pending pull request on 
Kohsuke's GitHub API on master 
(see https://github.com/kohsuke/github-api/pull/61) 

Change-Id: If53ddbbc90dd8e45de53caaf12a6e0fc69b8ee25