Sitelet https://web.archive.org/web/20221217050633/https://github.com/github/roadmap/issues/599
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fine-grained PAT expiry policies for organizations #599

Open
github-product-roadmap opened this issue Nov 16, 2022 · 0 comments
Open

Fine-grained PAT expiry policies for organizations #599

github-product-roadmap opened this issue Nov 16, 2022 · 0 comments
Labels
admin-cloud Feature area: Cloud administration beta Feature phase: Beta ecosystem Feature area: Ecosystem and APIs github enterprise Product SKU: GitHub Enterprise

Comments

@github-product-roadmap
Copy link
Collaborator

github-product-roadmap commented Nov 16, 2022

Summary

Fine-grained personal access tokens currently require all tokens to expire, but administrators who want specific expiration times must manually check each token to validate that they hew to an acceptable expiration time.

Rather than force developers to do a back-and-forth with their organization administrator to discover acceptable expiry times, we want to give administrators defined controls over the acceptable expiration times for fine-grained PATs in their organization.

This work provides organization administrators a policy for maximum acceptable expiry times in their organization. When a developer attempts to create a token with an expiry time longer than what's accepted, they'll immediately be told that a shorter expiration is required.

Intended Outcome

We don't want to force a back-and-forth discussion between administrators and developers around discovery of acceptable expiration times on tokens. Instead, administrators can set this value up front, and the developer will learn about it immediately as part of token creation.

This will allow more administrators to trust in the least privilege access of their developers, and remove their manual approval from the inner-loop of development.

How will it work?

Organization admins will be able to configure a policy in their organization around maximum acceptable token lifetimes. This policy will apply only to fine-grained PATs, and be enabled by default with an expiration maximum of 1 year.

During PAT creation, developers will see a note as soon as they select the organization as the resource owner, indicating the maximum acceptable expiry time.

@github github locked and limited conversation to collaborators Nov 16, 2022
@github-product-roadmap github-product-roadmap added admin-cloud Feature area: Cloud administration beta Feature phase: Beta ecosystem Feature area: Ecosystem and APIs github enterprise Product SKU: GitHub Enterprise labels Nov 16, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
admin-cloud Feature area: Cloud administration beta Feature phase: Beta ecosystem Feature area: Ecosystem and APIs github enterprise Product SKU: GitHub Enterprise
Projects
Status: Q1 2023 – Jan-Mar
Development

No branches or pull requests

1 participant