When working from places like corporate enterprise network, In order to avoid leakage of my main Bitbucket/Atlassian password, I use Bitbucket "app passwords".
When my job is over, I revoke the password.
However, I noticed that even if I revoke an app password, it remain usable.
For exemple, I am still able to clone a repo after revoking the associated app password.
Please note, that I use Windows manager-core.
`credential.helper=manager-core`
- Step 1 : delete any user entry in manager-core : with `git credential-manager-core erase`
- Step 2 : create an app-password within Bitbucket UI
- Step 3 : Clone with this password.
- Step 4 : revoke this app password
- Step 5 : delete local repo and try to clone again : it works !
Actually, i should not work as it has been revoked.
I thought, I'd have to wait some time for revocation to take effect : 24h later, i can still clone with thre revoked password.
Have you encountered a similar behaviour ?
Am i doing something wrong ?