Replies: 1 comment 4 replies
-
|
Hi, it is unclear to me how clients would work if the server is sending 2 separate WWW-Authenticate headers, one for Bearer, one for Basic. With regards to anonymous, given the discussion/findings discussed in #2928, for other registries such as Dockerhub, even anonymous uses a bearer token (we'd still need some customization to make that work though). |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hey there!
Just wanted to understand why the bearer authentication scheme has a special status? By special status, I mean that if enabled, it is the only authn method that can be used (authn.go#L58-L60). I was hoping to be able to have anonymous read-only access to the registry and pushes protected by a bearer token but with the current setup, it is not possible. Is there a reason behind this design decision?
Beta Was this translation helpful? Give feedback.
All reactions