Repository navigation
API key auth optional feature flag - #1909
Conversation
|
We need to make sure that this gets enabled as part of the upgrade, either via a user education handoff or possibly via an upgrade script. |
labkey-martyp
left a comment
There was a problem hiding this comment.
We need to make sure that this gets enabled as part of the upgrade, either via a user education handoff or possibly via an upgrade script.
Yes I think an upgrade script would be preferred as this will not be in production likely until well into 2027. Handling it now in a script ensures this is taken care of far down the road.
Due to security concerns, we want this off by default. I think a core upgrade script would be ill-advised. I could accept ONPRC- and SNPRC-specific upgrade scripts, but ONPRC (at least) will need to take another step: migrating to use the |
…eset optional feature. This way, it's not affected by signOut in the test.
|
@labkey-jeckels not sure how I "dismissed" your review, but I guess I did |
labkey-jeckels
left a comment
There was a problem hiding this comment.
Worth a confirmation on the try/finally approach before merging
## Rationale Authenticating via an API key provided as a URL parameter is not a security best practice, so we want to put this under an optional feature flag. LabKey/internal-issues#1617 ## Related Pull Requests - LabKey/clientModules#143 - LabKey/snprcEHRModules#1016 - LabKey/onprcEHRModules#1909 --------- Co-authored-by: Marty Pradere <martyp@labkey.com>
## Rationale Authenticating via an API key provided as a URL parameter is not a security best practice, so we want to put this under an optional feature flag. LabKey/internal-issues#1617 ## Related Pull Requests - LabKey/clientModules#143 - LabKey/snprcEHRModules#1016 - LabKey/onprcEHRModules#1909 --------- Co-authored-by: Marty Pradere <martyp@labkey.com>
Related Pull Requests