Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

create loophole in webSecure=true for sysactions #101

Merged
merged 1 commit into from
Sep 9, 2022

Conversation

joshuaauerbachwatson
Copy link
Contributor

This change opens a limited loophole in the new rule (as of deployer 4.3.0) that disallows webSecure: true. This rule should apply in most cases but the loophole relaxes it when the target namespace is nimbella. In DigitalOcean, as in the former Nimbella stack, this namespace is reserved for system actions (internal credentials are required to deploy to it). Some system actions need to use webSecure: true for various reasons.

@joshuaauerbachwatson joshuaauerbachwatson merged commit f8d63f9 into master Sep 9, 2022
@joshuaauerbachwatson joshuaauerbachwatson deleted the websecure-loophole branch September 9, 2022 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant