Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

do we want accessTokens to gate access to suri-rails? #92

Open
ndushay opened this issue Jun 10, 2020 · 2 comments
Open

do we want accessTokens to gate access to suri-rails? #92

ndushay opened this issue Jun 10, 2020 · 2 comments

Comments

@ndushay
Copy link
Contributor

ndushay commented Jun 10, 2020

or some other way to give it greater security?

I'm totally fine with the answer being "no" but thought I should ask, since it came up in a slack conversation I had with Justin Coyne.

@jcoyne
Copy link
Contributor

jcoyne commented Jun 17, 2020

I think we can fix the security with firewalls as requested here: https://github.com/sul-dlss/operations-tasks/issues/2271

@jmartin-sul
Copy link
Member

i would think so. the biggest security risks would seem to be

  1. something DoS-ish, e.g. someone accidentally or maliciously using up identifiers.
  2. minor information leakage -- seeing which IDs were already used.

i can't think of anything terrible that results from either, since the IDs are all random, though cleaning up after the first issue sounds like a pain.

so prob not super urgent, but seems like the right thing to do, and we have a pretty easy/established pattern at this point.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants