Skip to content

Conversation

@amvanbaren
Copy link
Contributor

Fixes #1377

  • Admins can revoke PATs for specific users via the admin panel.
  • Revoked tokens are immediately invalidated.
  • Users receive an automated email notification upon revocation.
  • All actions are logged for auditing purposes.

How to configure email: https://www.geeksforgeeks.org/springboot/spring-boot-sending-email-via-smtp/

@amvanbaren amvanbaren self-assigned this Nov 14, 2025
@netomi
Copy link
Contributor

netomi commented Nov 17, 2025

Tested the PR locally.

It did revoke all PATs for a given user by setting them to inactive.
Could not test the mail delivery yet.

@amvanbaren amvanbaren merged commit 457cece into eclipse:master Nov 19, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow admins to revoke a user's Personal Access Token (PAT)

2 participants