Project

General

Profile

Actions

Bug #16159

closed

Expire or invalidate token when logging out (logout)

Added by Tom Clegg about 4 years ago. Updated over 2 years ago.

Status:
Resolved
Priority:
Normal
Assigned To:
Category:
API
Target version:
Story points:
-
Release relationship:
Auto

Description

Logging out of workbench should invalidate the current token. (Currently, it just causes the browser to forget it.)

This means:

  1. workbench (1|2) logout includes API token to be revoked
  2. if a token is supplied, the logout route in controller expires the token

Workbench 2 "Get API token" creates new token (done)

Workbench 1 should tell the user that the token will expire when they log out, and provide a link to Workbench 2 dialog that creates a new API token.


Subtasks 2 (0 open2 closed)

Task #17481: Review 16159-token-expiration-on-logoutResolvedLucas Di Pentima04/08/2021Actions
Task #17533: Review 16159-logout-request-with-token (wb2 repo)Resolved04/13/2021Actions

Related issues

Related to Arvados Workbench 2 - Idea #16848: Token handling improvementsResolvedLucas Di Pentima02/17/2021Actions
Related to Arvados Epics - Idea #16520: GxP QualificationResolved08/01/202004/30/2021Actions
Related to Arvados Workbench 2 - Feature #17518: Workbench2 lets users auto-login and access dialogs through direct linksNewActions
Actions

Also available in: Atom PDF