Sandor Molnar created KNOX-3019:
-----------------------------------

             Summary: Allow tokens to be renewed any times
                 Key: KNOX-3019
                 URL: https://issues.apache.org/jira/browse/KNOX-3019
             Project: Apache Knox
          Issue Type: Improvement
          Components: Server, TokenGenerationUI
    Affects Versions: 2.0.0
            Reporter: Sandor Molnar
            Assignee: Sandor Molnar
             Fix For: 2.1.0


Setting the TTL to {{-1}} results in tokens that never expire. If the TTL is 
configured to a positive number, renewing the token is the only way to extend 
its expiration time. By default, there is a cap on this event: a token cannot 
be renewed after it reaches the configured maximum lifetime (defaults to {{{}7 
days{}}}).

This task aims to provide end-users with a way to bypass this check and let 
tokens be renewed whenever they want. The logic would be similar to the 
{{Unlimited token}} handling: if the maximum lifetime is set to {{{}-1{}}}, 
tokens would be subject to renewal without checking the maximum lifetime.

Please note that token renewal still must be configured with a list of trusted 
users via the {{knox.token.renewer.whitelist}} configuration.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to