Actions
Defect #44365
openOAuth Feature Enhancement
Status:
New
Priority:
Normal
Assignee:
-
Category:
Administration
Target version:
-
Resolution:
Affected version:
Description
We would like to use OAuth applications instead of API keys for REST API access because OAuth provides better security.
However, when a system administrator enables the REST API in Redmine, all users can use API keys, even if an OAuth application has been configured. This creates a potential security concern.
Therefore, we propose one of the following options:
- Disable the API key feature automatically when an OAuth application is registered.
- Provide a system setting to disable API keys.
- Add a role-based permission that allows administrators to control whether users can use API keys.
No data to display
Actions