-
Notifications
You must be signed in to change notification settings - Fork 25.8k
Hashing of access tokens values for storage #40765
Copy link
Copy link
Closed
Labels
:Security/AuthenticationLogging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)Logging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)blockerv7.2.0v8.0.0-alpha1
Description
Since #39631 the access token string is part of the token document ID. We should move forward with the planned changes regarding the hashing of the access token string before it becomes part of the token document id in the same version also ( 7.1 ).
This is required so that potential read access to the token security index will not allow for authentication.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
:Security/AuthenticationLogging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)Logging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)blockerv7.2.0v8.0.0-alpha1
Type
Fields
Give feedbackNo fields configured for issues without a type.