Skip to content
GitLab
Next
    • Why GitLab
    • Pricing
    • Contact Sales
    • Explore
  • Why GitLab
  • Pricing
  • Contact Sales
  • Explore
  • Sign in
  • Get free trial
  • GitLab.orgGitLab.org
  • GitLab FOSSGitLab FOSS
  • Issues
  • #18302

Private token should not be made available on the client side

Your private_token is currently available through gon.api_token which:

it’s as though my password is displayed...

--Stan

AFAIK private_tokens should never be available on the client side as they are the same as passwords.

cc @DouweM @rspeicher @stanhu @dzaporozhets

Assignee
Assign to
Time tracking