Skip to content

Commit e093f3a

Browse files
committed
added note about a future policy system to measure token age
1 parent 3459968 commit e093f3a

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

text/0068-org-user-token-restriction.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -76,4 +76,5 @@ Secret or API token leaks are commonplace:
7676

7777
- Allow organizations to require an SSO flow to authorize a user token before use.
7878
- Instead of a simple on/off toggle, we could create a more complex _policy_ system
79-
allowing user API tokens to be used for certain scopes within an org
79+
allowing user API tokens to be used for certain scopes within an org, meet
80+
required maximum lifetimes, etc.

0 commit comments

Comments
 (0)