jaracil / nexus

Distributed RPC system
Other
11 stars 2 forks source link

Extended "basic" authentication #21

Closed dpecos closed 8 years ago

dpecos commented 8 years ago

For our current use case, it's quite easy (or not hard enough) to copy "production credentials" to a dev environment and connect to nexus using that credentials.

Having whitelists and blacklists associated to a credentials could be quite handy to avoid these kind of problems. Relying only in the well-behaving of a person is risky.

pho commented 8 years ago

Per-user whitelist/blacklist has been implemented on 88847ac10aa897d759ad22a113818f4e6e4d833a