Per-package authorization
- Dominant language
- PHP
- Stars
- 3.3k
- Forks
- 530
- Avg merge
- 6h 53m
- Merged PRs (30d)
- 13
Description
Satis already supports authentication (via ssh certificate or http header), but there is no way to restrict user access to specific packages.
In a company with multiple developers working on different projects it is critical to restrict access to packages (especially when hosting proprietary code).
This is a feature request to add support for user authorization so that user A and user B can have access to distinct (but possibly overlaping) sets of packages hosted by the same repository.
Contributor guide
Research direction
No files, tests, or entry points are identified in the issue. First clarify the authorization model, how users and package sets are configured, and the expected behavior for overlapping access; done should include documented access rules and coverage for authorized and unauthorized package requests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- authorization
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100