How do the permissions assigned to app passwords work with the permissions placed directly on projects and repositories? Which takes precedence? I can't find any document that discusses this.
Example
I (as a workspace admin) assign a user Clone access directly to a single repository
The end user creates an app password so they can use git. When they create the app password, they give themselves read, write, admin and delete permissions to repositories.
What are the end user's effective permissions on repositories using git? Clone only as I assigned on that one repository or do they have read, write, admin and delete permissions to the repository as they specified in the app password permissions. I'm almost positive it's Clone only to that one repository but had to ask.
App passwords are a new concept to me so forgive the newbie question.