Expire Personal Access Token when OAUTH token expires #8647

Open
opened 2025-11-02 08:13:17 -06:00 by GiteaMirror · 0 comments
Owner

Originally created by @jasonvriends on GitHub (Mar 3, 2022).

Feature Description

When your OAUTH token expires, it should also change the 'is active' to disabled so the Personal Access Token no longer works. As of right now, if you log out of Gitea or no longer have access to login, your token still works until someone manually disables your account. This does not occur with Active Directory/LDAP.

Screenshots

No response

Originally created by @jasonvriends on GitHub (Mar 3, 2022). ### Feature Description When your OAUTH token expires, it should also change the 'is active' to disabled so the Personal Access Token no longer works. As of right now, if you log out of Gitea or no longer have access to login, your token still works until someone manually disables your account. This does not occur with Active Directory/LDAP. ### Screenshots _No response_
GiteaMirror added the type/proposaltopic/security labels 2025-11-02 08:13:17 -06:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#8647