Skip to content
Snippets Groups Projects
  • David M. Lee's avatar
    9ba976b1
    ARI authentication. · 9ba976b1
    David M. Lee authored
    This patch adds authentication support to ARI.
    
    Two authentication methods are supported. The first is HTTP Basic
    authentication, as specified in RFC 2617[1]. The second is by simply
    passing the username and password as an ?api_key query parameter
    (which allows swagger-ui[2] to authenticate more easily).
    
    ARI usernames and passwords are configured in the ari.conf file
    (formerly known as stasis_http.conf). The user may be set to
    `read_only`, which will prohibit the user from issuing POST, DELETE,
    etc. Also, the user's password may be specified in either plaintext,
    or encrypted using the crypt() function.
    
    Several other notes about the patch.
    
     * A few command line commands for seeing ARI config and status were
       also added.
     * The configuration parsing grew big enough that I extracted it to
       its own file.
    
     [1]: http://www.ietf.org/rfc/rfc2617.txt [2]:
     https://github.com/wordnik/swagger-ui
    
    (closes issue ASTERISK-21277)
    Review: https://reviewboard.asterisk.org/r/2649/
    
    
    
    git-svn-id: https://origsvn.digium.com/svn/asterisk/trunk@393530 65c4cc65-6c06-0410-ace0-fbb531ad65f3
    9ba976b1
    History
    ARI authentication.
    David M. Lee authored
    This patch adds authentication support to ARI.
    
    Two authentication methods are supported. The first is HTTP Basic
    authentication, as specified in RFC 2617[1]. The second is by simply
    passing the username and password as an ?api_key query parameter
    (which allows swagger-ui[2] to authenticate more easily).
    
    ARI usernames and passwords are configured in the ari.conf file
    (formerly known as stasis_http.conf). The user may be set to
    `read_only`, which will prohibit the user from issuing POST, DELETE,
    etc. Also, the user's password may be specified in either plaintext,
    or encrypted using the crypt() function.
    
    Several other notes about the patch.
    
     * A few command line commands for seeing ARI config and status were
       also added.
     * The configuration parsing grew big enough that I extracted it to
       its own file.
    
     [1]: http://www.ietf.org/rfc/rfc2617.txt [2]:
     https://github.com/wordnik/swagger-ui
    
    (closes issue ASTERISK-21277)
    Review: https://reviewboard.asterisk.org/r/2649/
    
    
    
    git-svn-id: https://origsvn.digium.com/svn/asterisk/trunk@393530 65c4cc65-6c06-0410-ace0-fbb531ad65f3