<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Token Restriction in URL in ArcGIS Enterprise Ideas</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-ideas/token-restriction-in-url/idi-p/1297866</link>
    <description>&lt;P&gt;We have security concern that generated token can be used by another user on different machine which all normal access on portal resources by capture the token during internal request within the portal, is there way to hide token or to make portal internal request in post&lt;/P&gt;</description>
    <pubDate>Sun, 11 Jun 2023 06:55:10 GMT</pubDate>
    <dc:creator>ahmedbadr2</dc:creator>
    <dc:date>2023-06-11T06:55:10Z</dc:date>
    <item>
      <title>Token Restriction in URL</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/token-restriction-in-url/idi-p/1297866</link>
      <description>&lt;P&gt;We have security concern that generated token can be used by another user on different machine which all normal access on portal resources by capture the token during internal request within the portal, is there way to hide token or to make portal internal request in post&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2023 06:55:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/token-restriction-in-url/idi-p/1297866</guid>
      <dc:creator>ahmedbadr2</dc:creator>
      <dc:date>2023-06-11T06:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Token Restriction in URL</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/token-restriction-in-url/idc-p/1308561#M3373</link>
      <description>&lt;P&gt;If you are referring to the personal token, that is generated when you access ressources while logged in to Portal, enable HTTPS. This should prevent users sniffing on the webtraffic to read out the tokens.&lt;BR /&gt;Of course, tokens should in now case be shared and should be treated like passwords.&lt;BR /&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/configure-https.htm" target="_blank" rel="noopener"&gt;Configure HTTPS—Portal for ArcGIS | Documentation for ArcGIS Enterprise&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/enforce-strict-https-communication.htm" target="_blank"&gt;Enforce strict HTTPS communication—Portal for ArcGIS | Documentation for ArcGIS Enterprise&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If you are referring to generated access tokens, you can limit token access to an specific IP Adress + expiration time&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonSchtte_ct_0-1689589272434.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/75514i083021FC358A8BA4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SimonSchtte_ct_0-1689589272434.png" alt="SimonSchtte_ct_0-1689589272434.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/specify-the-default-token-expiration-time.htm#:~:text=ArcGIS%20token%E2%80%94120%20minutes%20OAuth%20access%20token%2C%20when%20created,type%E2%80%9430%20minutes%20OAuth%20refresh%20token%E2%80%942%20weeks%20%2820%2C160%20minutes%29" target="_blank" rel="noopener"&gt;Specify the maximum token expiration time—Portal for ArcGIS | Documentation for ArcGIS Enterprise&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 10:25:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/token-restriction-in-url/idc-p/1308561#M3373</guid>
      <dc:creator>SimonSchütte_ct</dc:creator>
      <dc:date>2023-07-17T10:25:35Z</dc:date>
    </item>
  </channel>
</rss>

