Fedora Account System
Red Hat Associate
Red Hat Customer
Reproduction steps: 1. Configure a user in GLOBAL_READONLY_SUPER_USERS only. 2. Confirm the same user is not present in SUPER_USERS. 3. Apply config and allow Quay/operator reconciliation. 4. Log in as that user. 5. Navigate to robot account management and token views for a repo they are not a member of. 6. Observe that token visibility is allowed. Impact: Read-only administrative users can perform actions beyond intended scope. Robot account tokens are persistent by default (they do not expire), and depending on configuration can grant read (pull), write (push), or admin level access to container image repositories.