Skip to content

docs: server authentication as it actually works (breaking change, #45) - #18

Merged
elvogel merged 1 commit into
mainfrom
docs/server-auth
Sep 29, 2026
Merged

elvogel merged 1 commit into
mainfrom
docs/server-auth

Conversation

@elvogel

@elvogel elvogel commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Documents the REST server's authentication as it actually works since phoenixml main 0d46e91 (#45), and records the breaking change in the release notes.

Why this matters beyond freshness: the page described a design that doesn't exist ("authentication": {"type": "basic", "users": …}, and a client sending Username/Password). Config keys are case-insensitive, and the server now refuses to start when an Authentication section exists, so following the page produced a server that won't boot. The page also implied the gRPC server was authenticated. It isn't, and the page now says so.

Every setting, default and startup check was verified in source at 0d46e91 (AuthOptions, AuthOptionsValidator, AuthenticationSetup, Program.cs). The export example was run in bash, and site build is green (267 pages).

Not documented, per db-engine: OIDC and multiple providers, hashed keys (#50), status-only health (#51), gRPC auth. All of these are still coming.

🤖 Generated with Claude Code

https://claude.ai/code/session_019zMS2EzLV6KZG6ooYco8Uf

…ange

phoenixml main 0d46e91 (issue #45) made the REST server secure by default. This page documented
a different design that doesn't exist: an "authentication" section with "type": "basic", a users
table, and a client that sends Username/Password. It presented that as the server's security.
Worse, .NET config keys are case-insensitive, and the server now refuses to start when an
"Authentication" section exists, so following the page as written produced a server that
won't boot.

Replaced with the verified behaviour, checked against AuthOptions, AuthOptionsValidator,
AuthenticationSetup and Program.cs at 0d46e91, not taken on report: every endpoint needs an API
key (X-Api-Key) or an HS256 JWT; only /health* is open (and Swagger in Development); every Auth:*
setting with its default; the startup checks; the permission policies.

It also says plainly that the gRPC server has no authentication today. The page previously
implied it did.

Release notes: an "Unreleased: database server" entry for the breaking change. The database has
no tagged versions yet; users build it from source.

Facts supplied by the db-engine session; each one verified in source before writing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019zMS2EzLV6KZG6ooYco8Uf
@elvogel
elvogel merged commit 8fd2868 into main Sep 29, 2026
2 checks passed
@elvogel
elvogel deleted the docs/server-auth branch September 29, 2026 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant