eWaterCycle / eWaterCycle/remotebmi
Add security
未关闭
- 主要语言
- Julia
- 星标
- 0
- 派生
- 1
- PR 合并指标
- 30 天内没有已合并 PR
描述
By default communication is done over http without any authentication and authorization. This ok-ish for running locally where you trust the users on the system.
It would be nice if the web service could run on https with either self-signed certs or signed by trusted certificate authority like Let's encrypt.
To make sure the server can trust the client and vice versa we could use a shared secret like an API key or JWT.
See https://spec.openapis.org/oas/latest.html#security-scheme-object
The shared secret could be passed to the server using an environment variable.
贡献指南
评估
这个 Issue 还没有评估数据。