Users and sign-in
Not there yet
The PDM has no sign-in yet. Run it only on a network you trust, behind your VPN or your proxy's own authentication.
What exists today:
- The API takes the caller from the
X-Userheader. The web app's user menu sets it, so people can say who they are, and the audit log, reservations and releases carry that name. It's a label, not security. - With
NODE_ENV=production, the header is ignored and every request isDEV_USER. ADMIN_USERSlists the logins with administrator rights. Today that's one right: taking a release back.
What comes before the release:
- Sign-in through your identity provider, over OpenID Connect, so people use the accounts they already have.
- Projects: top-level folders with members and rights.