Conversation
…uthentication approval cache durations
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Folowing this issue
Adds a hierarchical resolution mechanism for the web-approval caching window (the "remember this browser approval for N minutes" setting), so it can be tuned per security profile instead of only globally.
Previously
web_approval_grace_period_secondswas a single globalParameterssetting. This adds the same field toUserandRole, and resolves it in priority order:At every level, unset (null) means "inherit from the next level down"; an explicit 0 means "disable caching at this level" and does not fall through further.
This lets admins give e.g. contractors a short/no caching window via their role while internal engineers keep the longer global default, with individual users still overridable on top.
AI Usage
Choose the level of AI involvement for this PR.
This is not to block AI contributions but rather to speed up PR review (saves time on trying to deduce the logic behind AI hallucinations).