Skip to content

Include tracking metadata with internal storage of user credentials #7818

@inickles

Description

@inickles

User credentials, such as web console session secrets and API access tokens should be associated with non-secret identifiers that can be used to reference the individual credential. This will be useful for:

  1. The ability to users and operators to list and revoke user credentials (Administrator API for disabling/removing device tokens #3892 and User API to list and revoke web console sessions and API tokens #7816).
  2. The ability to differentiate and track user sessions in the audit log.

While this was mentioned in #7816, tho I created a separate issue for it because it can be resolved independently and can benefit fit the audit log as well.

Metadata

Metadata

Assignees

Labels

customerFor any bug reports or feature requests tied to customer requestsenhancementNew feature or request.securityRelated to security.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions