Embedded view can create token

Rubena year ago

Hi,

I have just installed 5.6 and working well.
I have added a user with readonly rights for my embedded view.

But i can see that the readonly user can create a new token. Should that be right?

Anton Tananaeva year ago

Yes, that's correct.

Rubena year ago

okay.

shouldn't expact that when it's a read-only user.

Thanks

Anton Tananaeva year ago

Token is not stored anywhere, so readonly users can generate it.

Craig Rider4 months ago

Seems strange that a guest user (via token) has permission to create new tokens while also being able to set their own expiry date.

I guess my next step is to find out how to revoke tokens, sounds difficult it they're not saved.