Skip to content

HTTP Auth "Bleed Through" Fix#15

Open
cognusion wants to merge 1 commit into
nconf:masterfrom
cognusion:master
Open

HTTP Auth "Bleed Through" Fix#15
cognusion wants to merge 1 commit into
nconf:masterfrom
cognusion:master

Conversation

@cognusion

Copy link
Copy Markdown

Basically, if we disable NConf auth, but allow Apache (or whatever) to do it, which will (generally) set the REMOTE_USER variable, trust that. Has been in use since April in a pretty big shop, in combination with an LDAP-based SSO regime.

@gargiulo gargiulo closed this Dec 23, 2013
@gargiulo gargiulo reopened this Dec 23, 2013
@jekader

jekader commented Dec 31, 2013

Copy link
Copy Markdown

Great stuff, I also made a similar hack on my deployment, it still works nicely - users don't have to bother with entering passwords, and all their actions can be audited as usernames are stored in logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants