Skip to content
This repository has been archived by the owner on May 4, 2021. It is now read-only.

Admin Temporary Token has Full Access #32

Open
BNMoyers opened this issue Feb 6, 2020 · 0 comments
Open

Admin Temporary Token has Full Access #32

BNMoyers opened this issue Feb 6, 2020 · 0 comments

Comments

@BNMoyers
Copy link
Collaborator

BNMoyers commented Feb 6, 2020

Currently, the admin token expires after one day, but has full admin rights. This token is not encrypted and is included in the url; this creates a security issue for 24 hrs after the token is created.

Proposed solution: limit the token's access to creating a password if one doesn't already exist.

@wSedlacek wSedlacek changed the title Admin Access Admin Temporary Token has Full Access Feb 6, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant