11 ms·
Fine-grained personal access tokens for GitHub
- jgillich 4y agoWaited for this for so long! Thanks GitHub. But organization tokens would also be nice so you don't have to rely on one person to manage it.
- remram 4y agoApparently they are a different kind of token (github_pat_ instead of ghp_) in a separate part of the settings. So you can't just set the permissions of your existing tokens. An expiration date is also required for those new tokens with a max of 1 year.
- latchkey 4y agoThat 1 year max is a non-starter for me. I use PATs for things like a reverse proxy from CloudFlare workers to cache hits to a private repo accessed via the GH REST API. If I have to remember to rotate my keys every year, that's going to suck. What I want for this usecase is a non-expiring PAT that is Organization instead of User based and can be tied to a single repo.
- rad_gruchalski 4y agoCan’t you automate the rotation?
- latchkey 4y agoSure, but when does the russian doll end? Who implements the automation? How is it tested in CI? Who watches the automation to make sure it is working? Who fixes it when it is broken once a year. What happens if I get hit by a bus or leave the company? If Github could just solve the issue with a PAT that solves my usecase, it seems like a far less brittle solution.
- TechBro8615 4y agoIt doesn't end, that's why the number of developers is increasing indefinitely. The crazy thing is that it seems to work, as society has still yet to fall apart. ...or maybe society is falling apart and it's the fault of programmers. Maybe we're building an unstable web of automated abstractions supported by a decreasing number of specialists operating at the physical layers closer to reality. Maybe one day it will all collapse like the collaterized debt obligation market in 2007 and we'll be back to making websites with PHP and FTP.
- latchkey 4y ago> we'll be back to making websites with PHP and FTP It stopped?
- withinboredom 4y agoI def missed that memo.
- rad_gruchalski 4y ago> What happens if I get hit by a bus or leave the company? What happens now if you get hit by a bus and the token you issued is leaked, and someone has to rotate it? I would assume you have that documented, tested, preferably automated?
- chipsa 4y agoIf you have an automation to update it, why would you only run it once a year? why not once a week? then you'd know it's broken within a week.
- xani__ 4y ago
- kevincox 4y agoWhat access token does that automation use?
- deleted 4y ago[deleted]
- latchkey 4y agoNo. Turns out there is no way to automate it. PATs require sudo mode on GH.
- rad_gruchalski 4y agoThanks, turns out it's indeed impossible.
- derkades 4y agoGitHub automatically sends an email a week before expiry.
- latchkey 4y agoAmazing to think that there are a number of bits of critical infrastructure that are dependent on GitHub sending an email a week before it goes offline after running just fine for a year.
- insanitybit 4y agoGod I hope people aren't building critical infrastructure off of PATs. Use an app please.
- latchkey 4y agoapps won't work for all usecases.
- samcat116 4y ago> What I want for this usecase is a non-expiring PAT that is Organization instead of User based and can be tied to a single repo. Authenticating as a Github App will give you that capability.
- latchkey 4y agoWhich is a whole another set of issues and complexity.
- masklinn 4y ago> An expiration date is also required for those new tokens with a max of 1 year. Gah, so close, yet so far. But I guess that makes sense for personal tokens and I really need to finally look at applications, I assume they have fine-grained ACLs in the first place? Edit: > The permissions available to fine-grained personal access tokens are the same permissions available to GitHub Apps, and repository targeting works the same too.
- insanitybit 4y agoYes, if what you have is "I need persistent, scoped access" you want an app. The fact that so many people on HN are saying "ah darn it expires" is truly frightening and I hope Github publishes a deprecation plan for PAT classic.
- masklinn 4y ago> The fact that so many people on HN are saying "ah darn it expires" is truly frightening It’s also completely unsurprising: it’s very easy to grow a small PAT-based tool into a large PAT-based system, Apps is a significant overhead for a small too, and the migration path is not simple. And things get a lot worse when trying to create automation for your company, as your now need to involve the organisation owners / admins in order for them to set up and configure the GHA via a fun game of Simon Says.
- insanitybit 4y agoHopefully they deprecate PAT-classic so that people stop doing things the easy way with god-credentials.
- jtokoph 4y agoShouldn't things that expire like access tokens and certificates actually last slightly longer than these fixed calendar lengths to make renewal or rotation possible on the same day/week every year? For example, if I generate this token on Jan 1, 2023 and it lasts 1 year, I'll now need to generate the new one around December 21st, 2023 to make sure I have some lead time to deal with issues and not wait until the last second. Now, when I rotate the second time, I need to do it around December 14th, 2024...
- xani__ 4y ago
- KenoFischer 4y agoThis is absolutely a step in the right direction. GitHub permissions are ridiculously coarse-grained. Hopefully this will lead to more fine-grained permissions on GitHub in general.
- psygn89 4y agoI migrated from BitBucket recently and was surprised at how BitBucket was often ahead of GitHub in CI and API breadth. I guess I mistakenly thought GitHub would be miles ahead with its popularity and backing.
- another_devy 4y agoSay what? last time used it, check boxes in markdown still didn’t work there and CI was cheap knock-off of GitLab which doesn’t properly work with OAuth
- OJFord 4y agoI haven't used BitBucket for years, so I'm not commenting on that specifically - but to me it makes sense that the underdog necessarily forges ahead, because it needs some differentiator to persuade people away from the market leader.
- aniforprez 4y agoBitBucket ahead of GitHub? Where and how? Their pipelines was woefully underbaked and had tons of issues last I used it which was about 2 years ago. Pipelines was incredibly slow compared to Actions and was missing most of the features Actions has. You can't even define scheduled jobs from within the YAML file. You need to schedule them outside through the repository settings. It's also missing tons of triggers and the documentation is horrendous I've not used their APIs but GitHub's is pretty huge. I highly doubt BitBucket's API is any better
- ocdtrekkie 4y agoI'm always a little amazed when major tech platforms just now manage to get API tokens that are as configurable as MMOs from a decade or two ago. Glad to finally see it.
- princesse 4y agoWould love to know more about those configurable MMOs you mention. Anything in particular I could read/watch?
- Macha 4y agoEve Online. Both the official API and a lot of the community made stuff for corps (guilds) like TEST, Brave or Goonswarm.
- ocdtrekkie 4y agoYeah, that's the main one I had in mind. API key lets you select what characters to include, which features are visible for that API key, etc. I want to say I wrote code that interacted with these back in 2012 or so and this wasn't new. Meanwhile GitHub just got scoped API keys in 2022. Cloudflare got scoped API keys maybe last year or two years ago? Like to me this has felt like a baseline of API token design for a long time.
- JoshTriplett 4y agoI'm hoping this leads to being able to set the permissions for GitHub Actions tokens as well. For instance, an organization should be able to say "the token for this action should also have read-only access to check out other organization private repositories".
- atlgator 4y agoWay overdue. They should have launched this when the SolarWinds breach happened.
- candiddevmike 4y agoThere's a really nice HashiCorp Vault plugin to generate finely scoped JIT GitHub token: https://github.com/martinbaillie/vault-plugin-secrets-github https://github.com/martinbaillie/vault-plugin-secrets-github I use it with GitHub actions and TF.
- 0xbadcafebee 4y agoIf you're still using SSH to access your GitHub repos, please consider using HTTPS access tokens instead. The security is much more granular, they're easier to revoke and rotate, easier to generate and use safely, they work over HTTP proxies, you can specify a different user in the URL (https://myuser@github.com/ https://myuser@github.com/....) allowing for easier use of multiple accounts, and of course, you can use them for the GitHub API too. Security-wise, most people don't use SSH securely and may fall victim to MITM.
- anonymousDan 4y agoBut how do you manage them in practice? At least with ssh everything is in one place in my .ssh folder. I suppose I could create a .tokens folder or somesuch.
- 0xbadcafebee 4y agoGit has a lot of options for managing credentials ( https://git-scm.com/book/en/v2/Git-Tools-Credential-Storage https://git-scm.com/book/en/v2/Git-Tools-Credential-Storage https://git-scm.com/docs/gitcredentials https://git-scm.com/docs/gitcredentials https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-github#https https://docs.github.com/en/authentication/keeping-your-accou... ). For MFA: https://github.com/GitCredentialManager/git-credential-manager https://github.com/GitCredentialManager/git-credential-manag... The simplest thing is to create a ~/.netrc file: machine foobar.atlassian.net login myuser1@mycompany.com password isudfiusldifuslkjhdflksjhdf machine bitbucket.org login myotheruser password kjsdoihohuaoivhdifhuvoiadhf machine github.com login companyuser1 password ghp_oisjdofhowuefoiusiofus machine github.com login personaluser2 password ghp_jf9huiehuwfsouyewuhifuh machine circleci.com login myotheruser password lkjdhiufwhu8ef7yw8yoefhozheofuhouha4lhlWiur Clone a repository like git clone https://companyuser1@github.com/foo/bar.git https://companyuser1@github.com/foo/bar.git and Git will load the right login automatically.
- sneak 4y ago
- politician 4y agoAbout time.
- alexchantavy 4y agoAnyone know if there’s an API that lets you rotate these new tokens? Iirc this didn’t exist for the older ones. I looked at the linked docs but didn’t see anything.
- hirsin 4y agoThis is not supported for fine-grained PATs. Using apps for this, which have rotation as a requirement, is preferred.
- simonw 4y agoIt looks like you HAVE to set an expiry on this new shape of token? That's frustrating (though you can at least set it to an arbitrary far future date - though apparently limited to a year). I tend to use this kind of token for automations - where I have code running outside of GitHub that needs access to something. I very rarely want to limit that by time. Having to remember to rotate the access token every X months is annoying. I care much more about audit logs and the ability to easily revoke a token. Is there an argument for why non-expiring tokens are a bad idea that I'm missing here?
- hartator 4y ago> Is there an argument for why non-expiring tokens are a bad idea that I'm missing here? I don't think you are missing anything. And your full account is anyway hackable if you lose access to your email or phone number.
- xani__ 4y ago> Is there an argument for why non-expiring tokens are a bad idea that I'm missing here? it's a band-aid on other people not being able to secure their system. Band-aid that solves nothing as if token valid for a week or a month leaks you're still fucked. Now no expiry at all is a problem (you don't want someone digging out token from 2 years ago from somewhere to still work), but the node actively using service should be able to re-generate its own one. Then you could also get away by super-short tokens (say week) that app just re-generates every few days. For example app can use tokenN to generate tokenN+1 and have both of them be valid at the same time for a period (so app cluster have time to propagate the new access token before old one expires) And so any leak of old data would be no threat, you wouldn't need to have months-long human-regenerated tokens, and it would be more leak-proof as just having week old token would be inconsequential. Vs "bother someone every 6 months to click thru the stupid panel and put the key in right places just so your infrastructure keeps working". MS already does that in other places, it's aisine
- samcat116 4y agoYou'll want to look at Github Apps as thats closer to how those works vs how personal access tokens work. Apps have a private key that is associated to Github, which is used to create and sign JWTs that are valid for some period.
- soulofmischief 4y agoLong overdue. Tokens have been a huge security hole for a long time. Glad to see this finally get some attention.
- babl-yc 4y agoAre OAuth apps able to take advantage of these fine-grained APIs? Last time I checked, there was no read-only permission available for OAuth apps and you were required to create a one-off Github account with limited permissions. https://docs.github.com/en/developers/apps/building-oauth-apps/scopes-for-oauth-apps https://docs.github.com/en/developers/apps/building-oauth-ap...
- wintron 4y agoYou'll want to use a GitHub App[0] for that -- GitHub Apps use the same permissions model that these new token types are using. [0] https://docs.github.com/en/developers/apps/building-github-apps/creating-a-github-app https://docs.github.com/en/developers/apps/building-github-a...
- dyml 4y agoThis is great! It has always been a peeve that they have been so coarse grained. Thank you to the team members that made this happen.
- CGamesPlay 4y agoDo these new tokens still require the organization and user consent? I’m not able to use GitPod as a freelancer because my clients don’t want to approve the application so GitPod can’t access the repo. I work around the issue by creating a private repo with my SSH private key that has the client’s code as a submodule and configures GitPod to fetch the submodule using that ssh key. It’s silly that I have to do that.
- samcat116 4y agoGitPod is likely configured as a Github App and not something that uses a personal access token. So nothing here changes that.
- extantproject 4y agohttps://archive.ph/qIOhw https://archive.ph/qIOhw
- cube2222 4y agoFinally. The fact that so far any token reasonably operating on repositories had to have the full repo scope and, as far as I'm aware, the repo scope allows making public repos private (which resets all traction you've ever got: stars, forks, etc.), or delete them all together, was ridiculous. Now there's a separate "Repository Administration" scope. Moreover, you had to create purpose-suited GitHub accounts if you wanted to do cross-repo GitHub Actions (like updating a homebrew repo), and grant them access to only that repo, if you didn't want to have that GitHub Action have full access on your level. So yeah, finally. Time to decommission all these existing tokens. Thanks GitHub!
- cube2222 4y agoHas somebody already found the access level required to make IntelliJ accept this new kind of token?
- insanitybit 4y agoGod, "finally" was exactly my response. I can't believe how bad Github's ACLs and permissions are. This is much needed, our PATs are one of our most significant risks so we have jobs to audit them etc but... I just don't want them to be god mode just so that we can have scripts create repositories.
- robertlagrant 4y agoTotally agree. I can't believe it's been so poorly implemented up until now.
- prepend 4y agoHallelujah! I finally have a reason to update my tokens that GitHub has been bugging me about. Each time I would read all their perfectly good suggestions and then not change my tokens.
- modeless 4y agoI like GitHub based comment systems like Utterances and Giscus, but when you try to leave a comment you get a permission request page that says it can "act on your behalf" in your account which is ridiculously broad (and I think not actually true?). Will they be able to fix that now?
- hirsin 4y ago"Act on your behalf" is a common (and not great) way of indicating that the app will do <above permissions> wearing your nametag. It doesn't give the app blanket permissions against your account, just that it gets to do the above things _in your name_ rather than just as itself (`modeless posted this comment` versus `Utterances posted this comment`)
- brtknr 4y agoSo happy this is finally here! Been waiting months for this!!
- pcj-github 4y agoAt least five years overdue; glad this finally happened.