Skip to content
Discussion options

You must be logged in to vote

… guess… if you are interposing a proxy in front of the registry, that proxy could rewrite the WWW-Authenticate header as well?

Maybe? Forwarding token requests and responses though a proxy seems like something that authentication systems might want to actively protect against, see various “audience” fields in Open ID tokens and the like.

I think this protocol is simple / naive enough that just editing the headers, and forwarding bearer tokens, would work fine. But I have little experience with proxies of this kind.

Replies: 4 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by PaleNeutron
Comment options

You must be logged in to vote
4 replies
@vrothberg
Comment options

@PaleNeutron
Comment options

@PaleNeutron
Comment options

@mtrmac
Comment options

Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants