While looking at the readme again, i've realized that my current setup just doesn't need any kind of authentication. Looking again at the readme I think, that the provided docker command also has authentication disabled (it uses --authentication-keys-directory but not --authentication=true - i've copied the relevant args from the docker command and felt safe due to the --authentication-keys-directory).
Ways to fix it:
Leave authentication disabled by default but enable it when --authentication-keys-directory or --authentication-password is used
doesn't break anything
may create problems, when users rely on default pubkey directory
Remove the --authentication flag and don't use default values for pubkey directory or password. If the user want's authentication he has to explicitly specify the directory or the password.
only breaks slightly (as the --authentication flag is now unknown and will throw an error)
One flag less to worry about
Users using the default pubkey directory are still insecure after upgrading (if they assumed that authentication was enabled by default or when they place keys in the directory)
Enable authentication by default and (maybe) replace the --authentication flag by --disable-authentication to be more explicit.
breaks all unauthenticated setups (and all others when also changing the flag)
User has to explicitly make it insecure/public
Option 3 is the safest option, but I wouldn't mind using option 2 to keep some backwards compability
The text was updated successfully, but these errors were encountered:
I agree option 3 is likely best but I don't want to make an issue for users that are already using a 1.x release. We could propose a breaking change as part of 2.x, but I don't have many other features planned that would warrant a 2.x release. I think option 2 should work, but I'll give this a bit more thought before making a decision on it.
While looking at the readme again, i've realized that my current setup just doesn't need any kind of authentication. Looking again at the readme I think, that the provided docker command also has authentication disabled (it uses
--authentication-keys-directorybut not--authentication=true- i've copied the relevant args from the docker command and felt safe due to the--authentication-keys-directory).Ways to fix it:
--authentication-keys-directoryor--authentication-passwordis used--authenticationflag and don't use default values for pubkey directory or password. If the user want's authentication he has to explicitly specify the directory or the password.--authenticationflag is now unknown and will throw an error)--authenticationflag by--disable-authenticationto be more explicit.Option 3 is the safest option, but I wouldn't mind using option 2 to keep some backwards compability
The text was updated successfully, but these errors were encountered: