Added ACKEE_ANONYMOUS Environmental Variable For Allowing Users To View The Ackee UI Without Logging In#278
Open
Zozman wants to merge 4 commits intoelecterious:masterfrom
Open
Added ACKEE_ANONYMOUS Environmental Variable For Allowing Users To View The Ackee UI Without Logging In#278Zozman wants to merge 4 commits intoelecterious:masterfrom
Zozman wants to merge 4 commits intoelecterious:masterfrom
Conversation
|
Someone is attempting to deploy a commit to a Personal Account owned by @electerious on Vercel. @electerious first needs to authorize it. |
Owner
|
Thanks for the PR! There was already a similar experiment, but we couldn't find a way to protect the UI while keeping the /api endpoint public. |
Author
|
Could we mark tokens then to know if they had been generated with or without a password and then only let the /api endpoint's more sensitive operations work if the token was generated with credentials? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
As described in Issue #276, if a user has their instance of Ackee behind a reverse proxy, then it is possible that they might want to handle authentication on the proxy level instead of on the Ackee level. Therefore this PR adds a
ACKEE_ANONYMOUSvariable that when set totruewill automatically generate a session when opening the UI instead of prompting the user for credentials. This even makes it possible to run an instance of Ackee without aACKEE_USERNAMEandACKEE_PASSWORDeven set.