Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support anonymous access #126

Merged
merged 1 commit into from
Nov 5, 2021
Merged

Conversation

shizhMSFT
Copy link
Contributor

@shizhMSFT shizhMSFT commented Nov 3, 2021

Fixes #124

Signed-off-by: Shiwei Zhang <[email protected]>
@shizhMSFT shizhMSFT requested a review from a team November 3, 2021 07:17
@sajayantony
Copy link
Contributor

Should we remove Basic Auth from notation?

@shizhMSFT
Copy link
Contributor Author

Should we remove Basic Auth from notation?

As a security product, yes, we should remove basic auth. Could you create an issue for this?

@shizhMSFT
Copy link
Contributor Author

shizhMSFT commented Nov 3, 2021

However, it might be OK to use basic auth since it is about availablity. If we reject basic auth, then users cannot even pull the image from lots of registries.

Besides, notation signatures are designed to be transferring via an insecure channel. It works even if the registry is not trusted.

@shizhMSFT shizhMSFT changed the title Enhance Authentication Flow Support anonymous access Nov 3, 2021
Copy link
Contributor

@SteveLasker SteveLasker left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@SteveLasker SteveLasker merged commit 20657de into notaryproject:main Nov 5, 2021
@shizhMSFT shizhMSFT deleted the adv_auth branch November 7, 2021 03:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Bug] 401 Unauthorized on Public Registries
3 participants