kamax-matrix / mxisd

Federated Matrix Identity Server
GNU Affero General Public License v3.0
223 stars 115 forks source link

Review child project "pam-auth-rest-api" #186

Closed maxidorius closed 5 years ago

maxidorius commented 5 years ago

A community member created a child project and requested our feedback. We are more than happy to oblige!

Project: https://github.com/vranki/pam-auth-rest-api Original request: https://matrix.to/#/!NPRUEisLjcaMtHIzDr:kamax.io/$1560934249174895QprvM:matrix.org?via=kamax.io&via=matrix.org&via=matrix.veritasgenetics.com

vranki commented 5 years ago

I'm the author of the project. It's really small & written in about one hour so there may be issues. I haven't tested it against mxisd yet but that's the next step.

Only localpart and password are used for authentication. Is this ok or does it pose some security issue?

You can also create issues under the project as needed.

maxidorius commented 5 years ago

The size or complexity of your project is not important. You did create a project which build on top of ours, which we are very grateful for. It is only normal for us to take the time to review it as you took the time to review mxisd docs.

Only localpart and password are used for authentication. Is this ok or does it pose some security issue?

That's perfectly fine in this case and how mxisd is setup. We do the same in the other Identity stores.

You can also create issues under the project as needed.

Will do if needed, thanks!

maxidorius commented 5 years ago

This project is no longer maintained.