プロジェクト

全般

プロフィール

Vote #64038

未完了

HTTP Basic authentication for feeds

Admin Redmine さんがほぼ4年前に追加. ほぼ4年前に更新.

ステータス:
New
優先度:
通常
担当者:
-
カテゴリ:
Feeds_18
対象バージョン:
-
開始日:
2008/10/24
期日:
進捗率:

0%

予定工数:
category_id:
18
version_id:
0
issue_org_id:
2078
author_id:
2427
assigned_to_id:
0
comments:
1
status_id:
1
tracker_id:
2
plus1:
0
affected_version:
closed_on:
affected_version_id:
ステータス-->[New]

説明

Hi,

First of all, let me say that Redmine is a great product. However, I recently noticed that the feed URLs generated by Redmine include the key necessary to grant access to the content. I am not too comfortable with this solution because I am afraid that users will pass URLs around causing a security issue.

It would be nice to have the possibility to use HTTP Basic authentication instead. Coupled with SSL, it is a simple approach that works with many feed readers and doesn't have the aforementioned issue. I am not particularly familiar with Ruby on Rails, but according to this blog entry[1], it seems like an easy thing to do.

[1] http://www.rorsecurity.info/journal/2007/10/18/http-authentication-and-feed-security.html


journals

This has also been discussed in the forums, see message#23769.
--------------------------------------------------------------------------------

Admin Redmine さんがほぼ4年前に更新

  • カテゴリFeeds_18 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0