Merge branch 'viewer-auth' into rc173 (SECURITY.md update)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
+6
-3
@@ -98,6 +98,10 @@ current dataset has tokens, the endpoints below answer `401` unless the request
|
||||
`/start` replaces the previous tokens, so a run started without them is open, and the next run's
|
||||
users cannot read this one. No endpoint returns the tokens; the broker only compares strings
|
||||
(constant-time) and keeps them in memory. Whoever runs `/start` hands the token to the viewers.
|
||||
An accepted `/start` also clears what the previous run left readable - its statistics, plots and
|
||||
buffered images - in the same step that installs the new tokens, so the previous run is never
|
||||
served under the new tokens, and the new run's name never under the old ones. A refused `/start`
|
||||
(wrong state, invalid settings) changes nothing.
|
||||
|
||||
| Endpoint | With tokens set |
|
||||
|----------|-----------------|
|
||||
@@ -123,6 +127,5 @@ users cannot read this one. No endpoint returns the tokens; the broker only comp
|
||||
clear unless a TLS reverse proxy fronts the broker (§1); on a facility network this raises the bar
|
||||
from "type the IP" to "capture packets", which is the aim. It does not authenticate users or
|
||||
control, does not touch the ZeroMQ streams (issue #3), and `/status`'s free-text `message` may
|
||||
still quote a path. A Kerberos / GSSAPI single sign-on through a pass-through reverse proxy remains
|
||||
the option for sites that want user identity; the viewer's libcurl client (with Kerberos on Linux,
|
||||
SSPI on Windows) can negotiate against such a proxy.
|
||||
still quote a path. Datasets of different users within one session are separated by their tokens
|
||||
alone; there is no long-lived login.
|
||||
|
||||
Reference in New Issue
Block a user