Disallow changing the owner of an API token #11674

Closed
opened 2025-12-29 21:48:22 +01:00 by adam · 0 comments
Owner

Originally created by @jeremystretch on GitHub (Oct 2, 2025).

Originally assigned to: @jeremystretch on GitHub.

NetBox version

v4.4.2

Feature type

Change to existing functionality

Proposed functionality

Disallow the reassignment of an existing API token to a new user.

Use case

While the reassignment of a token to a new user allows for a change in ownership without replacing tokens on API clients, it also presents a moderate security concern. Prohibiting this would improve security of the NetBox APIs overall.

Database changes

N/A

External dependencies

N/A

Originally created by @jeremystretch on GitHub (Oct 2, 2025). Originally assigned to: @jeremystretch on GitHub. ### NetBox version v4.4.2 ### Feature type Change to existing functionality ### Proposed functionality Disallow the reassignment of an existing API token to a new user. ### Use case While the reassignment of a token to a new user allows for a change in ownership without replacing tokens on API clients, it also presents a moderate security concern. Prohibiting this would improve security of the NetBox APIs overall. ### Database changes N/A ### External dependencies N/A
adam added the status: acceptedtype: featurebreaking changecomplexity: low labels 2025-12-29 21:48:22 +01:00
adam closed this issue 2025-12-29 21:48:22 +01:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#11674