Merge branch 'viewer-auth' into rc173 (SECURITY.md update)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
2026-09-27 13:24:45 +02:00
co-authored by Claude Fable 5.1
+6 -3
View File
@@ -98,6 +98,10 @@ current dataset has tokens, the endpoints below answer `401` unless the request
`/start` replaces the previous tokens, so a run started without them is open, and the next run's
users cannot read this one. No endpoint returns the tokens; the broker only compares strings
(constant-time) and keeps them in memory. Whoever runs `/start` hands the token to the viewers.
An accepted `/start` also clears what the previous run left readable - its statistics, plots and
buffered images - in the same step that installs the new tokens, so the previous run is never
served under the new tokens, and the new run's name never under the old ones. A refused `/start`
(wrong state, invalid settings) changes nothing.
| Endpoint | With tokens set |
|----------|-----------------|
@@ -123,6 +127,5 @@ users cannot read this one. No endpoint returns the tokens; the broker only comp
clear unless a TLS reverse proxy fronts the broker (§1); on a facility network this raises the bar
from "type the IP" to "capture packets", which is the aim. It does not authenticate users or
control, does not touch the ZeroMQ streams (issue #3), and `/status`'s free-text `message` may
still quote a path. A Kerberos / GSSAPI single sign-on through a pass-through reverse proxy remains
the option for sites that want user identity; the viewer's libcurl client (with Kerberos on Linux,
SSPI on Windows) can negotiate against such a proxy.
still quote a path. Datasets of different users within one session are separated by their tokens
alone; there is no long-lived login.