tigris icon indicating copy to clipboard operation
tigris copied to clipboard

Embed project name inside token

Open himank opened this issue 1 year ago • 0 comments

The secrets are attached to a single project, but the token has no information about the project, which means it can be used for a different project as long as it is valid.

Embedding project information in the token will avoid it then, if the token already has a project attached to it then reject the request of performing any operation on another project like creating a project.

himank avatar Feb 23 '23 19:02 himank