Graylog2 / Graylog2/graylog2-server
Support Bearer Tokens for authenticating instead of using a token in basic auth
- Dominant language
- Java
- Stars
- 8.1k
- Forks
- 1.1k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 217
Description
## Expected Behavior
When a user creates a token which can be used for authentication, it should be accepted by the server when passed as part of a `Authentication: Bearer ` header.
## Current Behavior
For token authentication, the server expects basic auth with the username set to the token and password to `token`. This is rather proprietary. Additionally, some systems which are otherwise capable of speaking to Graylog (e.g. the [telegraf prometheus plugin](https://github.com/influxdata/telegraf/tree/master/plugins/inputs/prometheus) speaking to the [Graylog prometheus metrics reporter](https://github.com/graylog-labs/graylog-plugin-metrics-reporter/tree/master/metrics-reporter-prometheus) do not work due to the nonacceptance of Bearer Tokens.
## Possible Solution
## Steps to Reproduce (for bugs)
1.
2.
3.
4.
## Context
## Your Environment
* Graylog Version:
* Elasticsearch Version:
* MongoDB Version:
* Operating System:
* Browser version:
Contributor guide
Assessment
This issue has not been assessed yet.