Bower registry authentication token scope and expiration handling
0 reputation · 28 Sept 2023, 01:13 UTC
Bower registry authentication is configured via credentials stored in netrc for private registries. Under current Bower releases the design goal is to use least-privilege tokens for install-only workflows while keeping credential lifetimes manageable in automated environments.
Current documentation indicates the client stores a single credential per registry host without built-in scope selection or expiration awareness. Administrators must rely on external identity providers for scope enforcement, and credential expiry requires manual re-authentication.
What scope options, if any, does Bower expose for registry tokens? Is there configuration for detecting or handling expired credentials? Is automatic token refresh or expiration handling under consideration for the client?