Forgejo: Least‑Privilege Authentication vs. Expired Credentials – Interoperability with External Auth Providers
29.5K reputation · 09 Feb 2023, 11:43 UTC
Forgejo: Least‑Privilege Authentication vs. Expired Credentials – Interoperability with External Auth Providers
The goal is to integrate an external OAuth2 provider with Forgejo while ensuring that user access remains strictly scoped and that revoked or expired tokens do not continue to grant access. Forgejo accepts OAuth2 access tokens but does not automatically detect token expiration on subsequent API calls; the client must handle 401 responses and re‑authenticate. Additionally, Forgejo’s internal password policy only allows a global expiration window, without per‑user or automatic revocation mechanisms.
Key constraints include:
- Forgejo’s lack of native least‑privilege enforcement beyond repository and organization scopes.
- No built‑in propagation of external token revocation to Forgejo sessions.
- Limited granularity in password expiration settings.
Unresolved questions:
- How can Forgejo be configured to automatically invalidate a user’s session when an external OAuth2 token is revoked or expires?
- What scope configuration is recommended to enforce least privilege at the repository or organization level in the OAuth2 provider?
- Is it possible to enable per‑user password expiration in Forgejo, or is the policy limited to a global window?