yuluo-yx opened a new pull request, #4436: URL: https://github.com/apache/hertzbeat/pull/4436
## What's changed? - Disable Digest authentication in the default server, Docker, and Docker Compose configurations while retaining Basic and JWT compatibility. - Add a standard-library Python authentication contract suite covering anonymous 401 responses without browser challenges, form login, valid and invalid JWTs, Basic authentication, and token refresh. - Run the authentication contract suite as a distinct backend image E2E CI step and statically verify that all distributed configurations use the same defaults. - Document the Basic/JWT defaults, explicit Digest opt-in, browser prompt behavior, JWT-only configuration, restart requirement, and TLS guidance in the English and Chinese deployment guides. Related discussion: https://github.com/apache/hertzbeat/discussions/4415 Digest remains fully supported when explicitly enabled. Its initial `401 WWW-Authenticate: Digest` response is required by the protocol; suppressing that response based on browser-specific request headers would break standard Digest clients. The fix therefore removes Digest from mixed default authentication rather than changing its handshake semantics. ## Checklist - [x] I have read the [Contributing Guide](https://hertzbeat.apache.org/docs/community/code_style_and_quality_guide). - [x] I have written the necessary doc or comment. - [x] I have added authentication contract tests; runtime execution is delegated to this PR's backend image E2E job. ## Add or update API - [x] I have added the necessary [e2e tests](https://github.com/apache/hertzbeat/tree/master/e2e); runtime execution is delegated to this PR's backend image E2E job. ## Validation - `python3` source compilation passed. - Shell syntax validation passed. - Quick-start Compose expansion and authentication-default checks passed. - `git diff --check` passed. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
