Skip to content

[QUESTION/BUG] Is the "90-day expiration" for the granular tokens still enforced? #1864

@oleksandr-danylchenko

Description

@oleksandr-danylchenko

Issue

The banner at the top of the npmjs.com page clearly states that:

Security Update: Classic tokens have been revoked. Granular tokens are now limited to 90 days and require 2FA by default. Update your CI/CD workflows to avoid disruption. Learn more.

However, I can choose an arbitrary date in the future for a new granular token using the npm page 👀

IIRC, previously, right after the security rules update, the dropdown calendar didn't allow selection of anything past the 90 days. The dates appeared as disabled.

Demo

long_living_granular_token_creation_flow.mp4
Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions