mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add separate max token lifetime for administrators (#18267)
# Add separate token lifetime limits for administrators This PR introduces a new configuration option `--max-admin-token-lifetime` that allows administrators to create API tokens with longer lifetimes than regular users. By default, administrators can create tokens with a lifetime of up to 7 days (168 hours), while the existing `--max-token-lifetime` setting continues to apply to regular users. The implementation: - Adds a new `MaximumAdminTokenDuration` field to the session configuration - Modifies the token validation logic to check the user's role and apply the appropriate lifetime limit - Updates the token configuration endpoint to return the correct maximum lifetime based on the user's role - Adds tests to verify that administrators can create tokens with longer and shorter lifetimes - Updates documentation and help text to reflect the new option This change allows organizations to grant administrators extended token lifetimes while maintaining tighter security controls for regular users. Fixes #17395
This commit is contained in:
+4
@@ -332,6 +332,10 @@ NETWORKING / HTTP OPTIONS:
|
||||
The maximum lifetime duration users can specify when creating an API
|
||||
token.
|
||||
|
||||
--max-admin-token-lifetime duration, $CODER_MAX_ADMIN_TOKEN_LIFETIME (default: 168h0m0s)
|
||||
The maximum lifetime duration administrators can specify when creating
|
||||
an API token.
|
||||
|
||||
--proxy-health-interval duration, $CODER_PROXY_HEALTH_INTERVAL (default: 1m0s)
|
||||
The interval in which coderd should be checking the status of
|
||||
workspace proxies.
|
||||
|
||||
+4
@@ -25,6 +25,10 @@ networking:
|
||||
# The maximum lifetime duration users can specify when creating an API token.
|
||||
# (default: 876600h0m0s, type: duration)
|
||||
maxTokenLifetime: 876600h0m0s
|
||||
# The maximum lifetime duration administrators can specify when creating an API
|
||||
# token.
|
||||
# (default: 168h0m0s, type: duration)
|
||||
maxAdminTokenLifetime: 168h0m0s
|
||||
# The token expiry duration for browser sessions. Sessions may last longer if they
|
||||
# are actively making requests, but this functionality can be disabled via
|
||||
# --disable-session-expiry-refresh.
|
||||
|
||||
Reference in New Issue
Block a user