Skip to content

What are alternatives for currently existing authentication scheme? #1781

Answered by wolfgangwalther
bapcyk asked this question in Q&A
Discussion options

You must be logged in to vote

I think you should set up your pg_hba.conf, so that the authenticator user can only be logged in from the host that PostgREST is running on. So even if somebody steals the authenticator password in theory, they can't use it to login.

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
3 replies
@bapcyk
Comment options

@steve-chavez
Comment options

@bapcyk
Comment options

Comment options

You must be logged in to vote
2 replies
@bapcyk
Comment options

@wolfgangwalther
Comment options

Answer selected by bapcyk
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants