You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@ewdurbin said: By default, newly created tokens will have “user” scope, meaning that they’ll behave exactly like your password.
Are there plans to change this default so that using such a strong token is not the default so that people have to opt into it? (I’m no security expert so this is more inquisitive.)
As far as I know there are no such plans but I'd like @woodruffw and @nlhkabu to weigh in.
The text was updated successfully, but these errors were encountered:
An idea: We could add some additional UI on creation of a user-scoped token, warning the user that their new token will have access to all of their projects. This would allow us to retain it as a default (which I think is sensible, at least insofar as it doesn't make sense to choose a random project from the user's list as a default) while also making the security properties clear.
Followup to #994:
@brettcannon asks:
As far as I know there are no such plans but I'd like @woodruffw and @nlhkabu to weigh in.
The text was updated successfully, but these errors were encountered: