Post #2243551
2026-04-27 16:45 UTC
"3. CLI tokens have blanket permissions across environments.
The Railway CLI token I created to add and remove custom domains had the same volumeDelete permission as a token created for any other purpose. Tokens are not scoped by operation, by environment, or by resource at the permission level. There is no role-based access control for the Railway API — every token is effectively root. The Railway community has been asking for scoped tokens for years. It hasn't shipped."
equal blame here...
Replies (1)
-
@platypus@glammr.us 2026-04-27 16:46
cont... because THEY committed the CLI token to their repository? So if you've got these tokens and you haven't done simple due diligence to determine that they have superuser god powers, and then you commit to your repository? That's a you problem as well as a them problem.