yangbin1994 / blog

6 stars 0 forks source link

cnpmjs.org #15

Closed yangbin1994 closed 6 years ago

yangbin1994 commented 6 years ago
  1. 外网可访问,登陆设置白名单

public & scope mode & forcePublishWithScope

  • Everyone can install from this registry
  • Any logined user can publish, but modules must with scope @cnpm or @cnpmtest
  • Admins can unpublish any module, add author to any module

虽然任何人可以安装,但是测试将 always-auth 开启,还是需要登陆的;配合白名单,可以算得上安全

现在有个bug,就是授权开启的时候,给respsitory新增owner的时候会授权失败,暂时的解决方法就是分离仓库,和公用账号

  1. 只允许内网访问,登陆不设置白名单,授权关闭,进入内部扁平化世界,没有权限的限制