feat(grant): clean up expired grants
This commit is contained in:
+13
@@ -230,6 +230,19 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
|
||||
# Enable trash/recycle bin functionality (default: true)
|
||||
#OXICLOUD_ENABLE_TRASH=true
|
||||
|
||||
# Background daemon that deletes expired `storage.role_grants` rows.
|
||||
# The AuthZ engine already filters expired grants out of every
|
||||
# permission check at read time, so leaving expired rows in place is
|
||||
# a hygiene issue — not a security one. This purge deletes rows
|
||||
# whose `expires_at` is more than GRACE_DAYS in the past, preserving
|
||||
# the audit / support answer to "what happened to my access?" for
|
||||
# the grace window.
|
||||
#
|
||||
# Default: enabled. Recommended grace: >= 15 days.
|
||||
#OXICLOUD_GRANT_CLEANUP_ENABLED=true
|
||||
#OXICLOUD_GRANT_CLEANUP_GRACE_DAYS=15
|
||||
#OXICLOUD_GRANT_CLEANUP_INTERVAL_HOURS=24
|
||||
|
||||
# Enable search functionality (default: true)
|
||||
#OXICLOUD_ENABLE_SEARCH=true
|
||||
|
||||
|
||||
Reference in New Issue
Block a user