Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stop storing GitHub access_tokens for users #4222

Open
lucyb opened this issue Mar 21, 2024 · 0 comments
Open

Stop storing GitHub access_tokens for users #4222

lucyb opened this issue Mar 21, 2024 · 0 comments

Comments

@lucyb
Copy link
Contributor

lucyb commented Mar 21, 2024

We get this information when someone logs in via GitHub, from Django Social Auth and store it in the database. To the best of my knowledge we aren't using the token. Having it presents an extra security risk that we could easily avoid, so we should stop saving it to the database.

@lucyb lucyb changed the title Stop storing GitHub session tokens for users Stop storing GitHub access_tokens for users Mar 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant