Currently, the token has the full permission of the app. IMHO you should explicitly opt-in what permissions the new token should have.