@@ -36,7 +36,10 @@ There are three possible `credentials` settings at this point:
|
||||
The value `dangerously-allow-unauthenticated` was the old default.
|
||||
|
||||
The value `require` is the new default, so requests that were previously
|
||||
permitted may now start resulting in `401 Unauthorized` responses.
|
||||
permitted may now start resulting in `401 Unauthorized` responses. If you have
|
||||
`backend.auth.dangerouslyDisableDefaultAuthPolicy` set to `true`, this does not
|
||||
apply; the proxy will behave as if all endpoints were set to
|
||||
`dangerously-allow-unauthenticated`.
|
||||
|
||||
If you have proxy endpoints that require unauthenticated access still, please
|
||||
add `credentials: dangerously-allow-unauthenticated` to their declarations in
|
||||
|
||||
@@ -66,6 +66,10 @@ values:
|
||||
you also add `allowedHeaders: ['Authorization']` to an endpoint configuration,
|
||||
then the Backstage token (if provided) WILL be forwarded.
|
||||
|
||||
Note that if you have `backend.auth.dangerouslyDisableDefaultAuthPolicy` set to
|
||||
`true`, the `credentials` value does not apply; the proxy will behave as if all
|
||||
endpoints were set to `dangerously-allow-unauthenticated`.
|
||||
|
||||
If the value is a string, it is assumed to correspond to:
|
||||
|
||||
```yaml
|
||||
|
||||
Vendored
+16
-6
@@ -88,6 +88,11 @@ export interface Config {
|
||||
* are required to access this proxy target. The target can still
|
||||
* apply its own credentials checks, but the proxy will not help
|
||||
* block non-Backstage-blessed callers.
|
||||
*
|
||||
* Note that if you have
|
||||
* `backend.auth.dangerouslyDisableDefaultAuthPolicy` set to `true`,
|
||||
* the `credentials` value does not apply; the proxy will behave as
|
||||
* if all endpoints were set to `dangerously-allow-unauthenticated`.
|
||||
*/
|
||||
credentials?:
|
||||
| 'require'
|
||||
@@ -151,15 +156,20 @@ export interface Config {
|
||||
* The values are as follows:
|
||||
*
|
||||
* - 'require': Callers must provide Backstage user or service
|
||||
* credentials with each request. The credentials are not
|
||||
* forwarded to the proxy target.
|
||||
* credentials with each request. The credentials are not forwarded
|
||||
* to the proxy target.
|
||||
* - 'forward': Callers must provide Backstage user or service
|
||||
* credentials with each request, and those credentials are
|
||||
* forwarded to the proxy target.
|
||||
* - 'dangerously-allow-unauthenticated': No Backstage credentials
|
||||
* are required to access this proxy target. The target can still
|
||||
* apply its own credentials checks, but the proxy will not help
|
||||
* block non-Backstage-blessed callers.
|
||||
* - 'dangerously-allow-unauthenticated': No Backstage credentials are
|
||||
* required to access this proxy target. The target can still apply
|
||||
* its own credentials checks, but the proxy will not help block
|
||||
* non-Backstage-blessed callers.
|
||||
*
|
||||
* Note that if you have
|
||||
* `backend.auth.dangerouslyDisableDefaultAuthPolicy` set to `true`,
|
||||
* the `credentials` value does not apply; the proxy will behave as if
|
||||
* all endpoints were set to `dangerously-allow-unauthenticated`.
|
||||
*/
|
||||
credentials?:
|
||||
| 'require'
|
||||
|
||||
Reference in New Issue
Block a user