0
Provide a way to revoke leaked personal auth tokens during offboarding
Source: getsentry/sentry#126854 · opened by @sentry-junior[bot]
Problem Statement When an organization removes a member (including through SCIM), the member's personal auth tokens remain valid. The token no longer accesses that organization's data, but it can still access the account owner's profile. If a token is known to be leaked and the former member is unreachable, the organization has no way to revoke it. This came up in an enterprise offboarding report. No customer data exposure was identified. The underlying distinction is expected today: Sentry accounts and personal tokens belong to individuals, who may belong to multiple organizations. Related: #47474 (previously closed as expected behavior) and #119786 (configurable token expiration/TTL). Request Please consider a safe way to report and revoke a known-leaked personal token without requiring the account holder to be available, while preserving the separation between an individual's Sentry account and an organization's membership. Longer term, org-managed acc…
No pledges yet. Be the first to back this.
Comments
Similar requests
Configurable expiration (TTL) for personal and organization auth tokens
0 votes · 0 comments
[Feature Request] Add "Last Used" column to custom internal integration auth tokens
1 vote · 0 comments
API to Validate Auth Tokens
0 votes · 0 comments
Custom Integration - tokens need to have a expiry time
0 votes · 0 comments
Allow users to choose their preferred authenticator method by prioritizing Passkeys/Security Keys and the Authenticator App over Recovery Codes as the default 2FA methods.
0 votes · 0 comments
No comments yet.