yuluo-yx opened a new pull request, #4436:
URL: https://github.com/apache/hertzbeat/pull/4436

   ## What's changed?
   
   - Disable Digest authentication in the default server, Docker, and Docker 
Compose configurations while retaining Basic and JWT compatibility.
   - Add a standard-library Python authentication contract suite covering 
anonymous 401 responses without browser challenges, form login, valid and 
invalid JWTs, Basic authentication, and token refresh.
   - Run the authentication contract suite as a distinct backend image E2E CI 
step and statically verify that all distributed configurations use the same 
defaults.
   - Document the Basic/JWT defaults, explicit Digest opt-in, browser prompt 
behavior, JWT-only configuration, restart requirement, and TLS guidance in the 
English and Chinese deployment guides.
   
   Related discussion: https://github.com/apache/hertzbeat/discussions/4415
   
   Digest remains fully supported when explicitly enabled. Its initial `401 
WWW-Authenticate: Digest` response is required by the protocol; suppressing 
that response based on browser-specific request headers would break standard 
Digest clients. The fix therefore removes Digest from mixed default 
authentication rather than changing its handshake semantics.
   
   ## Checklist
   
   - [x] I have read the [Contributing 
Guide](https://hertzbeat.apache.org/docs/community/code_style_and_quality_guide).
   - [x] I have written the necessary doc or comment.
   - [x] I have added authentication contract tests; runtime execution is 
delegated to this PR's backend image E2E job.
   
   ## Add or update API
   
   - [x] I have added the necessary [e2e 
tests](https://github.com/apache/hertzbeat/tree/master/e2e); runtime execution 
is delegated to this PR's backend image E2E job.
   
   ## Validation
   
   - `python3` source compilation passed.
   - Shell syntax validation passed.
   - Quick-start Compose expansion and authentication-default checks passed.
   - `git diff --check` passed.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to