CD-SEC-03 - Authorization Misuse
OAuth tokens, refresh tokens, and API keys are provisioned broadly and persist indefinitely.
Intent & Description
'
π― Intent
Prevent over-provisioned and long-lived OAuth tokens, refresh tokens, and API keys that create zombie connections.
π Context
OAuth tokens, refresh tokens, and API keys are provisioned broadly “to avoid permission errors,” then persist indefinitely and get reused across apps and teams long after the original owner has moved on β creating “zombie connections.”
π‘ Solution
Implement scope reviews at provisioning time. Schedule re-authentication and token rotation. Monitor for over-shared or long-dormant connections. Disable implicit connection sharing by default. Use short-lived tokens with automatic expiration. Implement connection inventory management.'
Real-world Use Case
Source
π TL;DR
Manage OAuth tokens and API keys properly. Scope permissions at provisioning, rotate tokens regularly, and monitor for dormant connections.
Advantages
- Reduces zombie connection risk
- Enforces least privilege
- Improves security posture
- Enables connection lifecycle management
Disadvantages
- Token rotation operational overhead
- May break existing integrations
- Requires ongoing monitoring