Project

General

Profile

Actions

Defect #44365

open

OAuth Feature Enhancement

Added by yoshioka kazuaki about 17 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Administration
Target version:
-
Resolution:
Affected version:

Description

We would like to use OAuth applications instead of API keys for REST API access because OAuth provides better security.

However, when a system administrator enables the REST API in Redmine, all users can use API keys, even if an OAuth application has been configured. This creates a potential security concern.
Therefore, we propose one of the following options:
- Disable the API key feature automatically when an OAuth application is registered.
- Provide a system setting to disable API keys.
- Add a role-based permission that allows administrators to control whether users can use API keys.

No data to display

Actions

Also available in: Atom PDF