Skip to content

[P2] Separate implemented security behavior from future requirements and correct credential expiry #65

Description

@michielbdejong

Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.

Finding

SECURITY.md mixes descriptions of current behavior with future requirements/release gates. It still says proxy credentials have five-minute idle expiry, while store_connection_code issues ten-minute credentials. OAuth handoffs retain their separate five-minute lifetime. The document also uses Google-specific tenant-login terminology even though application login endpoints are configurable OIDC.

Evidence

Desired outcome

Clearly distinguish guarantees implemented today from outstanding requirements. Correct proxy-credential lifetime while preserving the separate handoff lifetime, and use accurate configurable-login terminology.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions