Page MenuHomePhabricator

Provide "bin/auth revoke" with a revoker for Conduit tokens
ClosedPublic

Authored by epriestley on Mar 3 2017, 10:22 PM.
Tags
None
Referenced Files
F18755505: D17458.id41984.diff
Sun, Oct 5, 5:54 AM
F18571025: D17458.id41984.diff
Wed, Sep 10, 4:18 AM
F18571017: D17458.id41984.diff
Wed, Sep 10, 4:17 AM
F18508605: D17458.id.diff
Sep 5 2025, 2:55 AM
F18500682: D17458.diff
Sep 4 2025, 9:15 PM
F18104296: D17458.diff
Aug 10 2025, 11:16 AM
F18094430: D17458.id.diff
Aug 7 2025, 10:07 PM
F18093853: D17458.id41983.diff
Aug 7 2025, 8:58 PM
Subscribers
None

Details

Summary

Ref T12313. This puts a UI on revoking credentials after a widespread compromise like Cloudbleed or a local one like copy/pasting a token into public chat.

For now, I'm only providing a revoker for conduit tokens since that's the immediate use case.

Test Plan
  • Revoked in user + type, everything + user, everywhere + type, and everything + everywhere modes.
  • Verified that conduit tokens were destroyed in all cases.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable