nightscout / nightscout.github.io

website, meta repo for whole project
GNU General Public License v2.0
107 stars 233 forks source link

Mention that Access tokens will be changed if API_SECRET is changed #110

Closed bjornoleh closed 3 years ago

bjornoleh commented 3 years ago

Hi,

It could be useful to mention that Access tokens will be changed if API_SECRET is changed. Just as a heads up for anyone that is already using tokens, so they know that any tokens already in use must be updated. Potentially a lot of apps/devices will be affected (family, other caretakers, various devices etc).

The latest release of NS now issues warnings about weak API_SECRET, so many users will be prompted to change theirs.

Probably this could be introduced here: http://nightscout.github.io/nightscout/security/#create-authentication-tokens-for-users

Side note: In NS, the tokens are called "Access tokens", but in the security documentation it is "Authentication tokens".

https://crowdin.com/translate/nightscout/18/en-nb#3514

psonnera commented 3 years ago

https://github.com/nightscout/nightscout.github.io/commit/1440817d762a062228bf032322cb4ac0fec2439e As for the side note it's been specified in a note since I don't want to break the link...

bjornoleh commented 3 years ago

@psonnera thanks!

Obs, typo?

Make sure ~your~ you update your devices and send the new token link to those you allowed to access your Nightscout

psonnera commented 3 years ago

@bjornoleh I'm lucky you're checking! Thanks.