Page MenuHomePhabricator

Prevent locked credentials from being made accessible via conduit
ClosedPublic

Authored by epriestley on May 18 2016, 7:35 PM.
Tags
None
Referenced Files
F18804999: D15944.id38387.diff
Sat, Oct 18, 1:01 PM
F18750462: D15944.id38393.diff
Sat, Oct 4, 7:51 AM
F18739526: D15944.id.diff
Wed, Oct 1, 9:48 PM
F18729492: D15944.diff
Tue, Sep 30, 11:13 AM
F18705319: D15944.id38388.diff
Sun, Sep 28, 10:48 AM
F18694259: D15944.diff
Sat, Sep 27, 2:54 AM
F18623910: D15944.diff
Sep 15 2025, 6:04 PM
F18471176: D15944.id38387.diff
Sep 2 2025, 6:54 PM
Subscribers
None

Details

Summary

Via HackerOne. Currently, you can use "Lock Permanently" to lock a credential permanently, but you can still enable Conduit API access to it. This directly contradicts both intent of the setting and its description as presented to the user.

Instead:

  • When a credential is locked, revoke Conduit API access.
  • Prevent API access from being enabled for locked credentials.
  • Prevent API access to locked credentials, period.
Test Plan
  • Created a credential.
  • Enabled API access.
  • Locked credential.
  • Saw API access become disabled.
  • Tried to enable API access; was rebuffed.
  • Queried credential via API, wasn't granted access.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Prevent locked credentials from being made accessible via conduit.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: chad.
  • Fix NoEffect exception if Conduit access is not enabled.
chad edited edge metadata.
This revision is now accepted and ready to land.May 18 2016, 9:33 PM
This revision was automatically updated to reflect the committed changes.