fe5f75930e
[master] Resolve "Personal access token with only `read_user` scope can be used to authenticate any web request" See merge request gitlab/gitlabhq!2583
5 lines
110 B
YAML
5 lines
110 B
YAML
---
|
|
title: Restrict Personal Access Tokens to API scope on web requests
|
|
merge_request:
|
|
author:
|
|
type: security
|