Page MenuHomePhabricator

Provide "bin/auth revoke" with a revoker for Conduit tokens
ClosedPublic

Authored by epriestley on Mar 3 2017, 10:22 PM.
Tags
None
Referenced Files
F14687518: D17458.diff
Mon, Jan 13, 4:27 PM
Unknown Object (File)
Fri, Dec 27, 7:44 AM
Unknown Object (File)
Dec 13 2024, 10:49 PM
Unknown Object (File)
Dec 9 2024, 3:28 PM
Unknown Object (File)
Dec 6 2024, 1:07 PM
Unknown Object (File)
Dec 5 2024, 3:43 PM
Unknown Object (File)
Dec 3 2024, 12:25 PM
Unknown Object (File)
Dec 2 2024, 2:53 PM
Subscribers
None

Details

Summary

Ref T12313. This puts a UI on revoking credentials after a widespread compromise like Cloudbleed or a local one like copy/pasting a token into public chat.

For now, I'm only providing a revoker for conduit tokens since that's the immediate use case.

Test Plan
  • Revoked in user + type, everything + user, everywhere + type, and everything + everywhere modes.
  • Verified that conduit tokens were destroyed in all cases.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable