dave2wave commented on issue #698:
URL: 
https://github.com/apache/tooling-trusted-releases/issues/698#issuecomment-4024470557

   > I have a question on this one - isn't clearing this up onbeforeunload a 
redundant place to do it? The DOM and JS structures on that page are torn down 
immediately after that event, so what benefit is there to clearing this data 
onbeforeunload?
   
   Note that the CSRF finding is **Low**. I'm inclined to agree with you.
   
   > On the token display ...
   
   If I understand the concern, it's a token leakage followed by continual 
re-use and extension. If that is theoretically going to extend use until the 
PAT expires then it's worth doing the timeout.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to