I'm developing an application which connects to JIRA using a user's credentials (through OAuth), but which only needs read access. Currently, when a user accesses the application, JIRA's OAuth authorization page says "The application foo would like to have read and write access to your data on foobar.atlassian.net" (emphasis theirs).
I'd rather request only read permissions, to prevent accidentally corrupting data and to reassure users that I don't intend to mess with their stuff. How can I configure things such that only read access is requested?