Skip to main content

Users and sign-in

Not there yet

The PDM has no sign-in yet. Run it only on a network you trust, behind your VPN or your proxy's own authentication.

What exists today:

  • The API takes the caller from the X-User header. The web app's user menu sets it, so people can say who they are, and the audit log, reservations and releases carry that name. It's a label, not security.
  • With NODE_ENV=production, the header is ignored and every request is DEV_USER.
  • ADMIN_USERS lists the logins with administrator rights. Today that's one right: taking a release back.

What comes before the release:

  • Sign-in through your identity provider, over OpenID Connect, so people use the accounts they already have.
  • Projects: top-level folders with members and rights.