POC: be able to bypass permissions using an admin token #181
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Soooo today I got fed up of seeing again stuff about having to "unprotect" an app to be able to run some curl requests, then having to protect-it-again-but-we-dont-really-know-if-it-was-protected-or-not-in-the-first-place
That turns a bunch of things that should have been simple into a complex mess.
So instead I'm investigating the idea of :
SSOwat-Admin-Token
ynh_local_curl
, we temporarily add such a token and inject the corresponding header in the requestTo test this PR:
install -m 400 -o www-data <(echo secret_token) /etc/ssowat/admin_token
curl
ing the page without any auth, this should show the ssowat portal title:curl -s -L https://yolo.test/hextris --insecure | grep title
--header "SSOwat-Admin-Token: secret_token"