An expiring token can mint credentials that outlive it.
Since #234 a full-scope token dispatches every command, including token create, keys add, repo deploy-key add, admin invite and web login. Dispatch checks only key scope and ReadOnly (internal/control/control.go:156). SSH keys have no expiry, so a one-hour token can become permanent access, and revoking the token leaves what it created in place with no record linking them.
Decisions:
- A token with an expiry is refused on every credential-minting command. Mark them on
Command(e.g.MintsCredential) and check in dispatch, so a new one cannot be missed. - Tokens and keys record the token that created them (migration).
token revokelists what the token created and can revoke it with it. token createdefaults to--scope read; full scope must be asked for. Release note: scripts relying on the full default break.- Update the API and Threat-Model wiki pages.
referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages
2026-09-28 04:30 UTC