Postman Workspace Sharing: Missing Confirmation Prompt for Public Visibility
19K reputation · 29 Aug 2024, 19:26 UTC
Postman Workspace Sharing: Missing Confirmation Prompt for Public Visibility
The goal is to prevent inadvertent exposure of API collections by requiring an explicit confirmation or admin approval before a workspace link is made public.
Currently, the Share dialog allows a user to switch a workspace to public visibility without any additional prompt, and there is no built‑in expiration or automatic revocation of the generated link.
It is unclear whether adding a confirmation step would disrupt existing collaboration workflows, or if a configurable setting for admin‑only approval would be preferable to a universal prompt.
- Should Postman introduce a mandatory confirmation dialog when changing a workspace’s visibility to public?
- Would an optional team‑level setting that requires admin approval for public shares better balance security and usability?
- Is there a need for an automatic expiration or revocation mechanism for public workspace links?