XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Trusted headers - auth plugin

    Scheduled Pinned Locked Moved Xen Orchestra
    6 Posts 3 Posters 231 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • geoffhouseG Offline
      geoffhouse
      last edited by

      Hi all.

      Loving your work...!

      We use Xen Orchestra behind a web proxy which handles our in-house authentication process.
      This proxy passes the authentication result as an HTTP header field (in our case 'remote_user').

      I've written a plugin to use this result and it seems to work nicely. Is this something I can share?
      Obviously this is completely insecure outside our use case, but works well for us (and maybe others).

      Thanks!
      Geoff

      1 Reply Last reply Reply Quote 0
      • geoffhouseG Offline
        geoffhouse
        last edited by

        Here's the code (if you're interested):

        https://github.com/geoffhouse/xo-server-auth-trustedheader

        1 Reply Last reply Reply Quote 0
        • olivierlambertO Offline
          olivierlambert Vates 🪐 Co-Founder CEO
          last edited by

          Thanks! I'm pinging @julien-f 🙂

          1 Reply Last reply Reply Quote 0
          • julien-fJ Offline
            julien-f Vates 🪐 Co-Founder XO Team
            last edited by

            @geoffhouse Nice!

            We don't have a process on how to handle external contributions like this one, we can integrate it to our main repository but we'll identify it as an external contribution and we'll mention you as maintainer if that's something you would want 🙂

            We'll probably be able to handle trivial fixes but I don't want to have something new to maintain.

            What do you think?

            geoffhouseG 1 Reply Last reply Reply Quote 0
            • geoffhouseG Offline
              geoffhouse @julien-f
              last edited by

              @julien-f That all sounds great - whatever works best for you guys. 🙂

              1 Reply Last reply Reply Quote 0
              • julien-fJ Offline
                julien-f Vates 🪐 Co-Founder XO Team
                last edited by

                The idea is to give the best visibility to your plugin 🙂

                Though I don't think we'll ship it directly to our customer because it's an advanced use case 😉

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post