Range-diff !488
back to !488 web login over SSH applies the login-link limit
-: ------- > 1: 9f77ab1 store: announce key revocations; LiveSSHKeys
-: ------- > 2: bf64c30 gitutil: Transport takes a cancel channel and kills its process group
-: ------- > 3: c096948 sshd: re-read the key per exec; revocation cuts its connections
-: ------- > 4: 2b84081 e2e: removing a key cuts its multiplexed connection and a push in flight
-: ------- > 5: 4bbf4f8 wiki: revocation closes open connections
-: ------- > 6: 4b94fa9 store: tokens and keys record the token that created them; chained revoke
-: ------- > 7: 89dd0a3 control: expiring credentials cannot run credential-minting commands
-: ------- > 8: dd36248 token: default --scope read; record the creating token; revoke --created
-: ------- > 9: ed682bb e2e: expiring tokens refused on minting; revoke --created
-: ------- > 10: 0787c7c wiki: token delegation, read default; release note
-: ------- > 11: e2a32d5 wiki: delegation bound covers tokens and keys, not web sessions
1: 2240cff = 12: cab50f5 store: ssh_keys.expires_at; expired keys are not live
2: f10d090 = 13: 7f5c45d sshd: refuse expired keys at auth and per exec; expiring keys cannot mint
3: 5fea0e6 = 14: 44e5fb3 keys: --ttl on keys add and repo deploy-key add; lists show last use and expiry
4: e54f028 ! 15: 1ed9fb9 wiki: key expiry
@@ .gitbay/wiki/Architecture/09-Controls.org: chapter names of OWASP ASVS 4.0 where
-| Credential expiry | partial | API tokens optional; SSH and deploy keys none (#277) |
+| Credential expiry | in place | optional =--ttl= on API tokens, SSH and deploy keys; checked at auth and per exec |
| Revocation takes effect immediately | in place | removing a key or disabling an account closes its connections; every exec re-reads its key (=internal/sshd/sshd.go=) |
- | Delegation bounded by the delegating credential | in place | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=) |
+ | Delegation bounded by the delegating credential | partial | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=); a web session can still mint credentials that outlive it (#297) |
## .gitbay/wiki/Architecture/10-Known-Gaps.org ##
@@ .gitbay/wiki/Users.org: A key's label is the comment on its =authorized_keys= li
## CHANGELOG.org ##
@@ CHANGELOG.org: must add =--scope full=. Existing tokens keep their scope.
- those too.
+ those too (#257).
- Removing an SSH key, a deploy key, or disabling an account closes the
connections the key opened, a push in flight included (#256).
+- =keys add= and =repo deploy-key add= take =--ttl=; an expired key is
5: 498c90d = 16: 03040d2 control: keys add refuses --ttl 0h and negative
6: 3a83e2a = 17: 2ddf238 control: token list uses expiresText, not relAge, for expiry
-: ------- > 18: 32a5f76 control: key lists fit 60 columns; headers clip with their column
-: ------- > 19: a8ba660 sshd: an expired key counts against the auth limiter
-: ------- > 20: 253e1a2 token: create refuses a zero or negative --ttl
7: bed7020 = 21: a6f7827 store: web sessions lapse after 12 hours idle, under the absolute cap
8: acc63bd ! 22: 0ff41e5 web: sessions list shows last use; docs for the idle timeout
@@ .gitbay/wiki/Architecture/09-Controls.org: chapter names of OWASP ASVS 4.0 where
+| Session lifetime | in place | 12 hours idle, 7 days absolute (=internal/store/sessions.go=) |
| Credential expiry | in place | optional =--ttl= on API tokens, SSH and deploy keys; checked at auth and per exec |
| Revocation takes effect immediately | in place | removing a key or disabling an account closes its connections; every exec re-reads its key (=internal/sshd/sshd.go=) |
- | Delegation bounded by the delegating credential | in place | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=) |
+ | Delegation bounded by the delegating credential | partial | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=); a web session can still mint credentials that outlive it (#297) |
## .gitbay/wiki/Architecture/10-Known-Gaps.org ##
@@ .gitbay/wiki/Architecture/10-Known-Gaps.org: what the 2026-09-27 review found; remove a row when its issue closes.
@@ .gitbay/wiki/Users.org: and deletes through the commands above.
## CHANGELOG.org ##
@@ CHANGELOG.org: must add =--scope full=. Existing tokens keep their scope.
- 15 seconds. An expiring key cannot create credentials, like an
- expiring token. =keys list= and =repo deploy-key list= gain =USED= and
=EXPIRES= columns, after the label (#277).
+ - =token list= at a terminal shows a future expiry as a time, not
+ "just now" (#286).
+- Browser sessions end after twelve hours without a request, and after
+ seven days as before. Sessions open at upgrade get a fresh twelve
+ hours. =web sessions list= shows when each was last used (#276).
-: ------- > 23: 08a7e44 changelog: the unreleased lead names the session idle timeout
9: dc058e2 = 24: 6f553fe web: login over SSH applies the login-link limit