Security docs missing several auth mechanisms

13 vues
Accéder directement au premier message non lu

Brad Wood

non lue,
7 juil. 2022, 13:42:1307/07/2022
à Undertow Dev
The docs here:
in the last sentence only list 4 auth mechanisms:

The built in mechanisms are FORM, DIGEST, CLIENT_CERT and BASIC.

However, this section of the docs 
has a table with 5 auth mechanisms:
  • BASIC
  • FORM - Is there any description of this and how it would work?  I've read the code, but I'm not clear exactly how or where I would use this.
  • CLIENT-CERT
  • DIGEST
  • EXTERNAL  - Is there any description of this and how it would work? I don't see any tests for it.
The following authentication mechanisms appear in the Undertow source code but are not mentioned in the docs.  Is this an oversight?
  • CachedAuthenticatedSessionMechanism
  • GenericHeaderAuthenticationMechanism
  • GSSAPIAuthenticationMechanism
  • SingleSignOnAuthenticationMechanism
Thanks!

~Brad

Developer Advocate
Ortus Solutions, Corp 

ColdBox Platform: http://www.coldbox.org 

Brad Wood

non lue,
20 juil. 2022, 13:59:1820/07/2022
à Undertow Dev
Any updates on these missing items from the docs?

Flavia Rainone

non lue,
21 juil. 2022, 02:48:3821/07/2022
à Undertow Dev
Hi Brad,

These authentication mechanisms were added a long time ago. Currently we use Elytron authentication mechanisms in WildFly and these classes haven't been updated for a long time.
It appears to me that the classes were added but the documentation was never updated.
I'll review this for Undertow 2.3 so we can get this corrected: https://issues.redhat.com/browse/UNDERTOW-2126

Best regards,
Flavia

Brad Wood

non lue,
21 juil. 2022, 10:57:2021/07/2022
à Flavia Rainone,Undertow Dev
Thanks for the info.  To be clear, I'm not using Wildfly, I'm just using Undertow directly.  Are you saying Undertow's auth mechanisms aren't supported any longer or shouldn't be used?

Thanks!

~Brad

Developer Advocate
Ortus Solutions, Corp 

ColdBox Platform: http://www.coldbox.org 


--
You received this message because you are subscribed to the Google Groups "Undertow Dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to undertow-dev...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/undertow-dev/32a2e786-3aed-487a-9fc4-1c6354713ac3n%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Flavia Rainone

non lue,
5 sept. 2022, 13:19:0905/09/2022
à Undertow Dev
Hi Brad,

They are supported. It is just something that went off the radar for quite a long time.

I gave this some thought and I decided I will make sure that the classes are updated. The documentation will also be corrected.

Best regards,
Flavia


Brad Wood

non lue,
5 sept. 2022, 14:17:0005/09/2022
à Flavia Rainone,Undertow Dev
Thanks for confirming Flavia!

~Brad

Developer Advocate
Ortus Solutions, Corp 

ColdBox Platform: http://www.coldbox.org 


Répondre à tous
Répondre à l'auteur
Transférer
0 nouveau message