Add custom instance wide prefix for tokens
-
Please check this box if this contribution uses AI-generated content (including content generated by GitLab Duo features) as outlined in the GitLab DCO & CLA. As a benefit of being a GitLab Community Contributor, you receive complimentary access to GitLab Duo.
What does this MR do and why?
This MR adds a flag to the application settings for instance wide token prefixes. It starts with support for feed_tokens, as they are easy to test and show the concept. I'll add support for other token types in follow-up MRs once this approach has been approved.
Currently, users can define a prefix for personal access tokens. Other token types, do not support custom prefixes yet.
This MR proposes to add an instance wide prefix, that is set to gl by default. The new prefix format is: #{instance_prefix}#{token_type_prefix}. E.g. for feed tokens, we'd get: #{instance_prefix}ft-. By default, this is the current token prefix glft-. However, we can now customize the instance prefix to create a new prefix: my-company-name-ft-.
With this custom prefix, it is easier to identify leaked tokens, because we can now skip all leaked tokens that start with gl. Now, we only need to look at tokens starting with my-company-name-.
References
MR acceptance checklist
MR Checklist ( @nwittstruck)
-
Changelog entry added, if necessary -
Documentation created/updated via this MR -
Documentation reviewed by technical writer or follow-up review issue created -
Tests added for this feature/bug -
Tested in all supported browsers -
Conforms to the code review guidelines -
Conforms to the merge request performance guidelines -
Conforms to the style guides -
Conforms to the javascript style guides -
Conforms to the database guides
Screenshots or screen recordings
How to set up and validate locally
- Enable feature flag via
rails c:
Feature.enable(:custom_prefix_for_all_token_types)
-
Run migrations with
bin/rails db:migrate(and down withbin/rails db:migrate:down:main db:migrate:down:ci VERSION=20250126160646) -
Change the
instance token prefixin the admin settings:Admin area > General > Account and limit > Instance token prefix, e.g. tomy-new-prefix -
Reset your feed token at
User Settings > Access tokens > Feed Token. It should now show a new token starting withmy-new-prefix.
Related to #388379

