composer / composer/satis

Per-package authorization

Open
#339 2 comments 12 reactions 0 assignees View on GitHub
feature
Dominant language
PHP
Stars
3.3k
Forks
530
Avg merge
6h 53m
Merged PRs (30d)
13

Description

Satis already supports authentication (via ssh certificate or http header), but there is no way to restrict user access to specific packages.

In a company with multiple developers working on different projects it is critical to restrict access to packages (especially when hosting proprietary code).

This is a feature request to add support for user authorization so that user A and user B can have access to distinct (but possibly overlaping) sets of packages hosted by the same repository.

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are identified in the issue. First clarify the authorization model, how users and package sets are configured, and the expected behavior for overlapping access; done should include documented access rules and coverage for authorized and unauthorized package requests.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.