Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Admin-level setting to enable/disable refreshable tokens #191

Closed
joeh90 opened this issue Jun 7, 2024 · 1 comment
Closed

Admin-level setting to enable/disable refreshable tokens #191

joeh90 opened this issue Jun 7, 2024 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@joeh90
Copy link

joeh90 commented Jun 7, 2024

Is your feature request related to a problem? Please describe.
The plugin can be used to issue a refreshable token to a user even if refreshable tokens are supposed to be disabled in Access settings (via token.allow-refreshable: false), thereby circumventing security of the system. This is of particular concern for Artifactory instances not using SCIM.

Describe the solution you'd like
Make allowRefreshable an admin-level setting in the plugin, to align with the Artifactory Access YAML setting. If false, users should not be able to be issued refreshable tokens via the plugin.

Describe alternatives you've considered
I've also raised a support ticket with JFrog seeking clarity on whether admin should be prevented from creating a refreshable token if the Access YAML prevents it. It's possible this should be considered a bug in Artifactory.

Additional context
N/A

@joeh90 joeh90 added the enhancement New feature or request label Jun 7, 2024
@joeh90
Copy link
Author

joeh90 commented Jun 10, 2024

We'll just configure Vault policies to deny these parameters.

@joeh90 joeh90 closed this as completed Jun 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants