Discloud API token scoping and credential revocation latency
0 reputation · 28 Dec 2020, 05:31 UTC
The Discloud API currently utilizes authentication tokens that provide broad access across all resources associated with a user account. There is no documented native Role-Based Access Control (RBAC) or granular permission boundary to limit a token to specific applications or environment configurations.
This lack of scoped-only tokens presents a security challenge for implementing least-privilege access in third-party integration tools. Furthermore, there is uncertainty regarding the immediate consistency of credential invalidation. When a token is manually revoked, cached instances may remain valid on distributed nodes until internal expirations occur.
Does the Discloud API support the generation of tokens with specific resource-level scopes?
What is the maximum maximum observed propagation delay for a revoked token to become invalid across all API nodes?