What do you all think about using oauth scopes to affect the response from a request?
For example, a person resource might have name, address, vital statics, criminal record, technical skills.
GET /dudes/thatduderightthere could be the single endpoint and method that's used to return a varying level of info based on oauth scope. His mom wouldn't see his criminal record, his lawyer would.
Part of me says hey, that's kind of cool. But most of me doesn't like it. Smells like trouble. Am I off base?
I'm sure there are pros/cons and this group seems like a great place to explore them. ;-)
Thanks,
Carlos