Skip to content

token is a huge security hole #162

Description

@alamothe

Bug Report

This plugin requires token to work. It simply says:

This token needs to be created by a registry owner with access to all organizations, teams, and repositories configured in your package access rules.

No matter how you deploy this, it is a giant security hole as other people in my company will be exposed to the token.

Versions

Version
Verdaccio 5
This plugin 5
Node 16

Expected behavior

Allow this plugin to operate without token.

Metadata

Metadata

Assignees

No one assigned

    Labels

    invalidThis doesn't seem right

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions