AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 51 Bitcoin

Merge pull request #7612 from minmoto/okjodom/store-credentials-permission

Public commit record

What the developer wrote

Authored by Nicolas Dorier

73/100 · Adequate
Merge pull request #7612 from minmoto/okjodom/store-credentials-permission

Add store permission for managing access tokens
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This change introduces a new, more specific permission called 'Manage access tokens' for store-level access token operations in BTCPay Server. Previously, viewing tokens required the broad 'View store settings' permission and creating or revoking tokens required the even broader 'Modify store settings' permission. The patch narrows those checks so that token management now uses its own dedicated permission. The new permission is automatically granted to the built-in 'Manager' role, and it is included by the existing 'Modify store settings' permission, so users who already had full store control keep the same access. This is a security hardening change that reduces the risk of lower-privileged users (for example, guests or employees) being able to create or revoke API access tokens if they had been accidentally given overly broad store settings rights.

Recommended action

No immediate action is required; this is a hardening patch. Operators should review custom store roles after upgrading to ensure they grant `btcpay.store.canmanagestorecredentials` where token management is intended, because only the built-in Manager role is automatically updated. Developers should confirm that no other token-related endpoints or API paths still rely on the broader store-settings permission.

Security signals we found

01

New fine-grained authorization policy introduced for sensitive credential-management operations

02

Controller actions and views switched from CanViewStoreSettings/CanModifyStoreSettings to CanManageStoreCredentials

03

Migration auto-grants new permission to the built-in Manager role to preserve expected access

04

Integration tests verify that lower-privileged roles (Employee, Guest) are denied token management

05

Policy is documented in swagger template

Risk score

Why this scored 51/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.