Project

General

Profile

Actions

Bug #16159

closed

Expire or invalidate token when logging out (logout)

Added by Tom Clegg almost 5 years ago. Updated about 3 years ago.

Status:
Resolved
Priority:
Normal
Assigned To:
Category:
API
Target version:
Start date:
04/08/2021
Due date:
% Done:

100%

Estimated time:
(Total: 0.00 h)
Story points:
-
Release relationship:
Auto

Description

Logging out of workbench should invalidate the current token. (Currently, it just causes the browser to forget it.)

This means:

  1. workbench (1|2) logout includes API token to be revoked
  2. if a token is supplied, the logout route in controller expires the token

Workbench 2 "Get API token" creates new token (done)

Workbench 1 should tell the user that the token will expire when they log out, and provide a link to Workbench 2 dialog that creates a new API token.


Subtasks 2 (0 open2 closed)

Task #17481: Review 16159-token-expiration-on-logoutResolvedLucas Di Pentima04/08/2021

Actions
Task #17533: Review 16159-logout-request-with-token (wb2 repo)Resolved04/13/2021

Actions

Related issues 3 (1 open2 closed)

Related to Arvados Workbench 2 - Story #16848: Token handling improvementsResolvedLucas Di Pentima02/17/2021

Actions
Related to Arvados Epics - Story #16520: GxP QualificationResolved08/01/202004/30/2021

Actions
Related to Arvados Workbench 2 - Feature #17518: Workbench2 lets users auto-login and access dialogs through direct linksNew

Actions
Actions

Also available in: Atom PDF