Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fine grained permissions for organization tokens #446

Open
o-l-a-v opened this issue Aug 14, 2024 · 0 comments
Open

Fine grained permissions for organization tokens #446

o-l-a-v opened this issue Aug 14, 2024 · 0 comments
Labels
kind/enhancement Improvements or new features

Comments

@o-l-a-v
Copy link

o-l-a-v commented Aug 14, 2024

This feature request exists for users, but not for organization tokens:

Currently, organization tokens are either "member" or "admin":

If one were to use an organization token for fetching audit logs using the audit log API:

One would have to add admin permissions to the token:

This does not follow the concept of least privelege.

Affected feature

Please implement the ability to give granular / fine grained permissions to org tokens, like only having the ability to read/get audit logs.

Examples:

@o-l-a-v o-l-a-v added the kind/enhancement Improvements or new features label Aug 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement Improvements or new features
Projects
None yet
Development

No branches or pull requests

1 participant