Skip to content

Oauth tokens should be visible and revokable in the user's account settings #9279

Description

@seanthegeek

The official GitHub CLI tool (or desktop app) and authenticate via a web browser, it uses an authentication token that is not visible or revokable anywhere in your account. When I reported this through the bug bounty program, I was told this is by design!

Any application or token with access to the account should appear in the list of account tokens — including for GitHub applications. Each listing should Include the application name, the user agent that added it, UTC timestamps for when the token was created and last used, and a big button to revoke it. An email should also be sent when a token is created.

Activity

  1. changed the title [-]Oauth tokens should be visible and revokable in the user's account[/-] [+]Oauth tokens should be visible and revokable in the user's account settings[/+] on Jul 2, 2024
  2. axi0m commented on Jul 2, 2024

    @axi0m

    I also support this enhancement.

  3. seanthegeek commented on Jul 2, 2024

    @seanthegeek
    Author

    Turns out I was just looking in the wrong spot. Oops! https://github.com/settings/applications

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions