In the discussion on obfuscation (#38) some security concerns came up.
It could make sense to provide guidance to the users to avoid giving them a false sense of security (as suggested by @enikao ).
My suggestion is to:
Indicate in the documentation that, while we provide an obfuscation mechanism, this should not be regarded as a way to make the application completely safe. We should indicate instead our recommended way to handle security
Output some message when obfuscation through the token is set, indicating that in some circumstances, this should not be enough and suggesting to look into the documentation for alternatives
As for the suggested method to handle security, we could suggest to use an authentication proxy in front of the lionweb repository. I would go as far as identifying a suggested one and provide a simple example on how to configure it. While this may need a little bit of work, that would far less work that implementing something in the LionWeb Repository itself.
In the discussion on obfuscation (#38) some security concerns came up.
It could make sense to provide guidance to the users to avoid giving them a false sense of security (as suggested by @enikao ).
My suggestion is to:
As for the suggested method to handle security, we could suggest to use an authentication proxy in front of the lionweb repository. I would go as far as identifying a suggested one and provide a simple example on how to configure it. While this may need a little bit of work, that would far less work that implementing something in the LionWeb Repository itself.
What do you think?