Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

API: token create/list/update with scopes[] and allow_list[] #19853

Assignees
ThomasK33
@ThomasK33

Description

@ThomasK33

Description

  • Extend token management endpoints to accept and returnscopes: string[] andallow_list: string[].
  • Validate requested scopes against the catalog; reject unknown names.
  • Enforce user’s role intersection: a scoped key cannot be used to mint a broader-scoped key than the caller is authorized to create.

Key files/areas

  • coderd/apikey.go handlers and request/response types.
  • Swagger annotations to update generated API docs.

Acceptance criteria

  • New request/response shapes reflected indocs/reference/api/* after generation.
  • Authorization tests cover “cannot mint elevated scopes”.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions


    [8]ページ先頭

    ©2009-2025 Movatter.jp