docs updates

Signed-off-by: Fredrik Adelöw <freben@gmail.com>
This commit is contained in:
Fredrik Adelöw
2024-05-07 12:40:26 +02:00
parent 88480e4ef2
commit f612f630ed
3 changed files with 24 additions and 7 deletions
+4 -1
View File
@@ -36,7 +36,10 @@ There are three possible `credentials` settings at this point:
The value `dangerously-allow-unauthenticated` was the old default.
The value `require` is the new default, so requests that were previously
permitted may now start resulting in `401 Unauthorized` responses.
permitted may now start resulting in `401 Unauthorized` responses. If you have
`backend.auth.dangerouslyDisableDefaultAuthPolicy` set to `true`, this does not
apply; the proxy will behave as if all endpoints were set to
`dangerously-allow-unauthenticated`.
If you have proxy endpoints that require unauthenticated access still, please
add `credentials: dangerously-allow-unauthenticated` to their declarations in
+4
View File
@@ -66,6 +66,10 @@ values:
you also add `allowedHeaders: ['Authorization']` to an endpoint configuration,
then the Backstage token (if provided) WILL be forwarded.
Note that if you have `backend.auth.dangerouslyDisableDefaultAuthPolicy` set to
`true`, the `credentials` value does not apply; the proxy will behave as if all
endpoints were set to `dangerously-allow-unauthenticated`.
If the value is a string, it is assumed to correspond to:
```yaml
+16 -6
View File
@@ -88,6 +88,11 @@ export interface Config {
* are required to access this proxy target. The target can still
* apply its own credentials checks, but the proxy will not help
* block non-Backstage-blessed callers.
*
* Note that if you have
* `backend.auth.dangerouslyDisableDefaultAuthPolicy` set to `true`,
* the `credentials` value does not apply; the proxy will behave as
* if all endpoints were set to `dangerously-allow-unauthenticated`.
*/
credentials?:
| 'require'
@@ -151,15 +156,20 @@ export interface Config {
* The values are as follows:
*
* - 'require': Callers must provide Backstage user or service
* credentials with each request. The credentials are not
* forwarded to the proxy target.
* credentials with each request. The credentials are not forwarded
* to the proxy target.
* - 'forward': Callers must provide Backstage user or service
* credentials with each request, and those credentials are
* forwarded to the proxy target.
* - 'dangerously-allow-unauthenticated': No Backstage credentials
* are required to access this proxy target. The target can still
* apply its own credentials checks, but the proxy will not help
* block non-Backstage-blessed callers.
* - 'dangerously-allow-unauthenticated': No Backstage credentials are
* required to access this proxy target. The target can still apply
* its own credentials checks, but the proxy will not help block
* non-Backstage-blessed callers.
*
* Note that if you have
* `backend.auth.dangerouslyDisableDefaultAuthPolicy` set to `true`,
* the `credentials` value does not apply; the proxy will behave as if
* all endpoints were set to `dangerously-allow-unauthenticated`.
*/
credentials?:
| 'require'