Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow admins to revoke authentication tokens #25307

Closed
butonic opened this issue Jun 30, 2016 · 5 comments
Closed

Allow admins to revoke authentication tokens #25307

butonic opened this issue Jun 30, 2016 · 5 comments

Comments

@butonic
Copy link
Member

butonic commented Jun 30, 2016

Currently, users can revoke a token themselves. Admins should be able to revoke them as well to remain in control.

@butonic
Copy link
Member Author

butonic commented Jun 30, 2016

@PVince81
Copy link
Contributor

Yeah, some ideas we discussed with @ChristophWurst for the UI:

  • provide a search field in the admin page to be able to search for a user and then display that user's sessions with "Disconnect" buttons.
  • maybe add a button "Disconnect all" too

Not sure if this should be a dedicated page.
Also thought about adding a link from the users page, but as I understand there are some user managers (shibboleth, IMAP?) where there is no user list so one still needs to be able to search by user to perform the operation.

@DeepDiver1975 DeepDiver1975 modified the milestone: backlog Jul 25, 2016
@PVince81
Copy link
Contributor

cc @tomneedham

I thought we had an occ command for this already

@tomneedham
Copy link
Contributor

Whats the roadmap for these token with OAuth now here? OCC commands should be around as well.

@PVince81
Copy link
Contributor

PVince81 commented Nov 2, 2017

I'm moving this to triage for future scheduling. @pmaier1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

6 participants