Closes #20823: Validate Token expiration date on creation #829

Closed
opened 2026-04-05 18:00:17 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @pheus on 11/21/2025

Fixes: #20823

This PR adds model-level validation to prevent creating API tokens with an expiration date in the past, while still allowing updates to existing tokens (including already-expired ones).

Changes:

  • Updates Token.clean() to raise a ValidationError when creating a new token (pk is None) whose expires timestamp is already in the past.
  • Leaves updates to existing tokens unchanged so that expired tokens can still be modified as needed.
  • Adds tests in users/tests/test_models.py covering:
    • the Token.is_expired property for None, future, and past expiration times
    • creation of tokens with a past expiration date
    • updates to existing expired tokens

No database or API schema changes are introduced by this PR.

*Originally created by @pheus on 11/21/2025* <!-- Thank you for your interest in contributing to NetBox! Please note that our contribution policy requires that a feature request or bug report be approved and assigned prior to opening a pull request. This helps avoid waste time and effort on a proposed change that we might not be able to accept. IF YOUR PULL REQUEST DOES NOT REFERENCE AN ISSUE WHICH HAS BEEN ASSIGNED TO YOU, IT WILL BE CLOSED AUTOMATICALLY. Please specify your assigned issue number on the line below. --> ### Fixes: #20823 <!-- Please include a summary of the proposed changes below. --> This PR adds model-level validation to prevent creating API tokens with an expiration date in the past, while still allowing updates to existing tokens (including already-expired ones). Changes: - Updates `Token.clean()` to raise a `ValidationError` when creating a new token (`pk is None`) whose `expires` timestamp is already in the past. - Leaves updates to existing tokens unchanged so that expired tokens can still be modified as needed. - Adds tests in `users/tests/test_models.py` covering: - the `Token.is_expired` property for `None`, future, and past expiration times - creation of tokens with a past expiration date - updates to existing expired tokens No database or API schema changes are introduced by this PR.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/netbox#829