Investigate non-plaintext token cache
Open
- Dominant language
- R
- Stars
- 48
- Forks
- 23
- Avg merge
- 4h 2m
- Merged PRs (30d)
- 3
Description
Email from Storage team
> according to the Storage Team’s security experts, it’s best to store the tokens in a secret store rather than exposing them as plaintext. We also had the same conversation with them when we were implementing OAuth authentication, and they advised us to not follow the CLI’s example, as it’s always possible that a malicious agent is running when the user is logged in.
Contributor guide
Assessment
This issue has not been assessed yet.