mandate plugin

Application Password Capabilities

Mandate Team @ wpmandate.com • 3 days ago

When you create an Application Password the app that uses that password gets all of the capabilities of the user, even if that app only needs some limited access. Perhaps the correct approach is to create a user for each Application Password / app combination who only has the capabilities needed, instead of using your own account? That is not something I thought of before, but it makes sense. In any event, this new plugin, Mandate, adds a policy / capabilities layer onto Application Password uses. It also provides expiration dates.