ACL Token "Last Used" Time
Open
theme/acls
theme/api
type/enhancement
type/umbrella-☂️
- Dominant language
- Go
- Stars
- 30.1k
- Forks
- 4.6k
- Avg merge
- 2d 6h
- Merged PRs (30d)
- 43
Description
#### Feature Description
It would be very helpful to have some information around when ACL tokens have been used for API access. Specifically when the token as last been used.
#### Use Case(s)
When rotating ACL tokens (and deprecating/deleting an old one), there is no easy way to determine if a token is no longer being used before deleting it. Currently, we are just setting all of the policies on the token to `deny` and hoping nothing breaks. A "LastUsed" time would go a long way to increasing confidence and safety when rotating production-used ACL tokens.
Contributor guide
Assessment
This issue has not been assessed yet.