ronnieroyston commented on issue #4663: URL: https://github.com/apache/couchdb/issues/4663#issuecomment-1619065193
The JWT signature acts as the password. Couch verifying that the `sub` is configured as an `_admin` does not make a username a secret or a password but adds additional security in that server admins must be explicitly configured. The option to reject `_admin` claims is valuable. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
