token: expiring tokens cannot mint credentials; record creator; default read scope #257

closed cmc opened this on 2026-09-28 02:36 UTC · control migration security

Discussion

cmc 2026-09-28 02:36 UTC

An expiring token can mint credentials that outlive it.

Since #234 a full-scope token dispatches every command, including token create, keys add, repo deploy-key add, admin invite and web login. Dispatch checks only key scope and ReadOnly (internal/control/control.go:156). SSH keys have no expiry, so a one-hour token can become permanent access, and revoking the token leaves what it created in place with no record linking them.

Decisions:

  • A token with an expiry is refused on every credential-minting command. Mark them on Command (e.g. MintsCredential) and check in dispatch, so a new one cannot be missed.
  • Tokens and keys record the token that created them (migration). token revoke lists what the token created and can revoke it with it.
  • token create defaults to --scope read; full scope must be asked for. Release note: scripts relying on the full default break.
  • Update the API and Threat-Model wiki pages.

referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages

2026-09-28 04:30 UTC

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

referenced in commit b711b70da5 by cmc: plans: apply decisions on the open questions

2026-09-28 06:16 UTC

referenced in commit e2a32d5f8d by cmc: wiki: delegation bound covers tokens and keys, not web sessions

2026-09-28 21:48 UTC

closed by cmc in commit 0787c7c07e: wiki: token delegation, read default; release note

2026-09-28 21:48 UTC

referenced in commit ed682bb8e7 by cmc: e2e: expiring tokens refused on minting; revoke --created

2026-09-28 21:48 UTC

referenced in commit dd36248950 by cmc: token: default --scope read; record the creating token; revoke --created

2026-09-28 21:48 UTC

referenced in commit 89dd0a3eba by cmc: control: expiring credentials cannot run credential-minting commands

2026-09-28 21:48 UTC

referenced in commit 4b94fa96a1 by cmc: store: tokens and keys record the token that created them; chained revoke

2026-09-28 21:48 UTC