965419b2b8f66cbb6b8c0f02dfc4509032e0fa64
CreateAPIToken capped a new token's role at the creator's role but never capped its scopes against the calling credential's scopes, and POST /api/tokens required only settings:write. A token holding settings:write alone could therefore mint a token holding keys:write or secrets:write, reaching every SSH private key and vault secret in the instance. createToken now refuses (403 scope_confinement) when the calling credential is itself a token and any requested scope is not satisfied by that token's own scopes, via services.ScopeSatisfied so servers:write still permits granting servers:read. Cookie sessions are unaffected, since their authority is the user's role. Also correct the createToken doc comment, which claimed the scope cap already existed. Also document why Hint stores 5 hex characters of the token secret.
Description
No description provided
9.7 MiB
Languages
JavaScript
63.9%
Go
19.3%
TypeScript
16.6%