Sonarqube github oauth login is secured over http?

47 views
Skip to first unread message

Kumar Gaurav

unread,
Apr 15, 2018, 9:04:16 AM4/15/18
to SonarQube
Dear All,  If I use github authentication plugin on http sonarqube then: Is login data secured over network?

So my sonar instance is: http:mysonar
And github url is: https://mygithub

If I login to mysonar, I am wondering how are my login data handled? Does it go directly to github for authentication? or does it go to Sonarqube first?

Thanks a lot,
Kumar

Kumar Gaurav

unread,
Apr 15, 2018, 9:35:29 PM4/15/18
to SonarQube
In github oauth description: "For security reasons HTTP is not supported. HTTPS must be used"

Regards,
Kumar

G. Ann Campbell

unread,
Apr 19, 2018, 9:04:48 AM4/19/18
to SonarQube
Hi Kumar,

You need a proxy in between.


Ann

Kumar Gaurav

unread,
Apr 19, 2018, 11:13:33 AM4/19/18
to SonarQube
Thanks Ann. I added a reverse-proxy in docker image.. works fine.. :)
Reply all
Reply to author
Forward
0 new messages