Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.
Finding
SECURITY.md mixes descriptions of current behavior with future requirements/release gates. It still says proxy credentials have five-minute idle expiry, while store_connection_code issues ten-minute credentials. OAuth handoffs retain their separate five-minute lifetime. The document also uses Google-specific tenant-login terminology even though application login endpoints are configurable OIDC.
Evidence
Desired outcome
Clearly distinguish guarantees implemented today from outstanding requirements. Correct proxy-credential lifetime while preserving the separate handoff lifetime, and use accurate configurable-login terminology.
Recorded during review of main at
a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.Finding
SECURITY.md mixes descriptions of current behavior with future requirements/release gates. It still says proxy credentials have five-minute idle expiry, while
store_connection_codeissues ten-minute credentials. OAuth handoffs retain their separate five-minute lifetime. The document also uses Google-specific tenant-login terminology even though application login endpoints are configurable OIDC.Evidence
Desired outcome
Clearly distinguish guarantees implemented today from outstanding requirements. Correct proxy-credential lifetime while preserving the separate handoff lifetime, and use accurate configurable-login terminology.