heroku / heroku/roadmap

Make Heroku CLI session expire (timeout) configurable

Open
#340 2 comments 2 reactions 1 assignee Claimed by @friism View on GitHub
Proposed
Dominant language
No language data
Stars
225
Forks
19
PR merge metrics
No merged PRs in 30d

Description

### Required Terms

- [x] I agree to follow this project's [Code of Conduct](https://github.com/heroku/roadmap/blob/main/CODE_OF_CONDUCT.md)
- [x] I have read and accept the [Salesforce Program Agreement](https://www.salesforce.com/company/program-agreement/)

### What service(s) is this request for?

Heroku CLI

### Tell us about what you're trying to solve. What challenges are you facing?

The Heroku CLI has a configurable --expires-in option during login, which has a default of 30 days. However, this doesn't seem to work when you have MFA enabled. Also it would be nice if you could configure a default per organization/team, to enforce it throughout the company instead of having to rely on every user to set this on every sign in. Would something like this be possible?

We think 30 days is rather long and would rather limit this to require a resign in when someone's laptop gets compromised.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.