docs: server authentication as it actually works (breaking change, #45) - #18
Merged
Merged
Conversation
…ange phoenixml main 0d46e91 (issue #45) made the REST server secure by default. This page documented a different design that doesn't exist: an "authentication" section with "type": "basic", a users table, and a client that sends Username/Password. It presented that as the server's security. Worse, .NET config keys are case-insensitive, and the server now refuses to start when an "Authentication" section exists, so following the page as written produced a server that won't boot. Replaced with the verified behaviour, checked against AuthOptions, AuthOptionsValidator, AuthenticationSetup and Program.cs at 0d46e91, not taken on report: every endpoint needs an API key (X-Api-Key) or an HS256 JWT; only /health* is open (and Swagger in Development); every Auth:* setting with its default; the startup checks; the permission policies. It also says plainly that the gRPC server has no authentication today. The page previously implied it did. Release notes: an "Unreleased: database server" entry for the breaking change. The database has no tagged versions yet; users build it from source. Facts supplied by the db-engine session; each one verified in source before writing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019zMS2EzLV6KZG6ooYco8Uf
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documents the REST server's authentication as it actually works since phoenixml
main0d46e91 (#45), and records the breaking change in the release notes.Why this matters beyond freshness: the page described a design that doesn't exist (
"authentication": {"type": "basic", "users": …}, and a client sending Username/Password). Config keys are case-insensitive, and the server now refuses to start when anAuthenticationsection exists, so following the page produced a server that won't boot. The page also implied the gRPC server was authenticated. It isn't, and the page now says so.Every setting, default and startup check was verified in source at 0d46e91 (
AuthOptions,AuthOptionsValidator,AuthenticationSetup,Program.cs). Theexportexample was run in bash, and site build is green (267 pages).Not documented, per db-engine: OIDC and multiple providers, hashed keys (#50), status-only health (#51), gRPC auth. All of these are still coming.
🤖 Generated with Claude Code
https://claude.ai/code/session_019zMS2EzLV6KZG6ooYco8Uf