confusion about authentication #4967
|
I just installed Verdaccio 6.0.0 ( My goal is to have a single Verdaccio user with a certain password and have a long-term NPM/Yarn configuration (though Kubernetes secrets) that is able to login to Verdaccio. User registration should be disabled (
I would be happy if you could help me understand how the configuration works. Thanks a lot in advance! The storage: /verdaccio/storage/data
web:
title: Verdaccio
auth:
htpasswd:
file: /verdaccio/htpasswd
max_users: -1 # do not allow users to register
uplinks:
npmjs:
url: https://registry.npmjs.org/
agent_options:
keepAlive: true
maxSockets: 40
maxFreeSockets: 10
packages:
'@myscope/*':
access: $authenticated
publish: $authenticated
'**':
access: $authenticated
proxy: npmjs
middlewares:
audit:
enabled: true # enable "npm audit"
log: {type: stdout, format: pretty, level: http} |
Replies: 3 comments 1 reply
Now you will have a correct
The secret is used to verify the jwt payload. If you change it, all existing tokens become invalid.
You are correct. The
As you can see here, it took yarn until v4 to get the login process working properly with Verdaccio. However, yarn 1 should work with |
@jampy @mbtools Since https://github.com/verdaccio/verdaccio/releases/tag/v5.31.0 was introduced You are using version 6.x you can use
yes, the secret is used for singing tokens, either if you use
If you don't use the
Only if you choose use JWT but by default (legacy) does not expires. Regarding JWT The request to the API can be set either For such cases you can use security:
web:
sign:
expiresIn: 1h # 1 hour by default
verify:
someProp: [value] |
@jampy @mbtools
the secret should be 64 characters long, not 32.corrections bellowSince https://github.com/verdaccio/verdaccio/releases/tag/v5.31.0 was introduced
migrateToSecureLegacySignaturein order to do that for you, of course with side effects (read the release)You are using version 6.x you can use
migrateToSecureLegacySignatureto fix that automatically for you.yes, the secret is used for singing tokens, either if you use
legacyorjwt.