Enable REST Engine HTTP Basic Authentication by default

XMLWordPrintable

    • Type: Task
    • Resolution: Won't Do
    • Priority: L3 - Default
    • None
    • Affects Version/s: 7.13.0-alpha4
    • Component/s: run
    • None
    • Environment:
      Kubernetes 1.16

      On top of CAM-11293, I propose that HTTP Basic Authentication should be enabled for REST engine out-of-the-box. Reasons:

      I'd also argue that having a demo:demo account is a bad idea. It should be an auto-generated password that is shown to console on first startup (and provides a way to reset it if missing), and this auto-generation can be turned off. In Kubernetes/Helm environment, the auto-generated password is saved to a Kubernetes secret, which makes it both secure and convenient. But this is another topic.

      Our experience with Camunda BPM Run: https://about.lovia.life/docs/infrastructure/camunda/

      cc tobias.metzke

            Assignee:
            Unassigned
            Reporter:
            Hendy Irawan
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: