Skip to content

If user is removed from GitHub team/org they should lose access (within X minutes) #67

@simonw

Description

@simonw

Last remaining issue for #64 - if Datasette is configured to only allow access to users who are members of a specific GitHub organization, we need to ensure they lose access within a reasonable timeframe.

Their teams and orgs are baked into their actor cookie.

It's OK for them to maintain access for a little while, provided that's documented and administrators know to e.g. rotate the DATASETTE_SECRET.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationenhancementNew feature or requestwontfixThis will not be worked on

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions