AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 51 Bitcoin

Add store permission for managing access tokens

Public commit record

What the developer wrote

Authored by okjodom

68/100 · Adequate
Add store permission for managing access tokens

Introduce btcpay.store.canmanagestorecredentials, included by
btcpay.store.canmodifystoresettings and granted to the built-in Manager
role. Store access tokens, pairing, and their navigation now require it,
so roles such as Guest no longer see or manage a store's access tokens.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This change adds a new, more specific permission for managing store access tokens in BTCPay Server. Previously, viewing or managing these tokens required only broad 'view store settings' or 'modify store settings' permissions, which meant lower-privileged roles like Guest could see or manage them. Now, a dedicated 'manage store credentials' permission is required, and it is automatically granted to the built-in Manager role. This is a hardening fix that reduces the risk of privilege misuse, but it is not a patch for a known active exploit.

Recommended action

Treat as a security hardening improvement. Review whether any custom store roles besides Manager previously relied on CanModifyStoreSettings to manage tokens and may need explicit CanManageStoreCredentials assignment. Ensure the migration runs successfully in deployments with existing Manager roles. No urgent patching is indicated by the supplied materials.

Security signals we found

01

Authorization boundary tightening: lower-privileged store roles (e.g., Guest) lose access to token management UI/actions

02

New granular permission reduces blast radius of 'modify store settings' permission

03

Database migration retroactively grants new permission to existing Manager role

04

Integration test added to enforce the new authorization behavior

05

No evidence of an active vulnerability, CVE, or security advisory in supplied materials

Risk score

Why this scored 51/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.