A browser session can mint credentials that outlive it.
#257 refuses credential-minting commands to a token or SSH key with an expiry. A web session also expires (12 hours idle, 7 days absolute, #276), but web dispatch (internal/httpd/control.go, runControlCode) builds a Ctx with no Expires, so through the settings forms a session can add a non-expiring SSH key, deploy key or runner key, or verify an email. A stolen session cookie can become a permanent SSH key.
- Set
Ctx.Expiresfrom the session's absolute expiry on web dispatch, soMintsCredentialcommands are refused the same way; or require a fresh login (re-authentication) for those forms. - Update Threat-Model and Architecture/09-Controls when it lands.
referenced in commit fb6e9dcfa4 by cmc: plans: #287, #284, #298, #285, #297
2026-09-29 00:09 UTC