Skip to content

Add (a potentially much better) timestamp_timeout: with a shorter PIN #5

@eugenesvk

Description

@eugenesvk

sudo has this timestamp_timeout option that doesn't re-prompt you for a password within, say, 5 minutes of entering a password

It seems that please doesn't have this option yet, but also I'd like to propose another modification that could make this option even better — slightly less convenient, but more secure — by using the concept of PINs, so instead of not re-prompting you for the full password during this timestamp_timeout period, the please command should instead prompt you every time, but not for your full password, but for a secondary, shorter password (aka "PIN")
This way you don't have to risk some wrong copy&paste or something worse doing anything as root within the blessed period

I understand that with proper more granular permissions this might not be as important, but at the same time not everyone will bother with granularity #1, so this is still useful and and improvement over the total passwordlessness!

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions