Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

interest check on basic auth for templates routes #359

Open
dzsquared opened this issue Jul 21, 2022 · 3 comments
Open

interest check on basic auth for templates routes #359

dzsquared opened this issue Jul 21, 2022 · 3 comments

Comments

@dzsquared
Copy link
Contributor

Due to the way I have my instance deployed, I’d like to protect the web UI routes with basic auth. Is there interest in incorporating an optional admin password for routes that render templates? If so, I can open a draft PR for more discussion based on the early implementation I have.

@tmack8001
Copy link
Collaborator

I'm not against this. Guessing @dzsquared you have this deployed in a publicly accessible way (makes sense to me) cause in that way you then have remote monitoring of your sessions like we had with the traditional mothership service.

If we were to include basic authentication it would be best to make it an opt-in feature. Ideally with a UI to configure and change the Basic Authentication setup which then gets printed into the config.yaml file where all other server settings are persisted.

@tmack8001
Copy link
Collaborator

A draft PR would be a great way forward to have a discussion on the direction and implementation of this. With a publicly accessible server deploy you may also want to limit the machine series APIs to only the machines that are configured / aliased by your server that way there is at least a bit of protection around random data points being created, though I doubt that is really a problem... I haven't seen this personally.

@chiefwigms
Copy link
Owner

I'm not against this. Guessing @dzsquared you have this deployed in a publicly accessible way (makes sense to me) cause in that way you then have remote monitoring of your sessions like we had with the traditional mothership service.

If we were to include basic authentication it would be best to make it an opt-in feature. Ideally with a UI to configure and change the Basic Authentication setup which then gets printed into the config.yaml file where all other server settings are persisted.

I'm of the opinion to keep it simple - a lot of the "features" seemingly have cluttered the code, but 🤷‍♂️. Like @tmack8001 said, I'd definitely make it opt-in though. Worst case, just make a auth branch and maintain any master updates? There are several users now so if this isn't a wide spread feature I don't want it breaking basic functionality.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants