Re: [DISCUSSION] turn off OOTB JWT authorization/SSO functionality

2019-01-21 Thread Michael Brohl
Thank you all, if there are no objections I will enhance the patch in [1] to make this configurable and switched off as default. Regards, Michael [1] https://issues.apache.org/jira/browse/OFBIZ-10814 Am 21.01.19 um 11:41 schrieb Dennis Balkir: +1 for off as default Am 21.01.19 um 10:03

Re: [DISCUSSION] turn off OOTB JWT authorization/SSO functionality

2019-01-21 Thread Dennis Balkir
+1 for off as default Am 21.01.19 um 10:03 schrieb Taher Alkhateeb: +1 to default off On Sat, Jan 19, 2019 at 7:25 PM Michael Brohl wrote: No, we are mainly discussing if we should turn off the JWT functionality in the default setting and what could be done to make the current implementation

Re: [DISCUSSION] turn off OOTB JWT authorization/SSO functionality

2019-01-21 Thread Taher Alkhateeb
+1 to default off On Sat, Jan 19, 2019 at 7:25 PM Michael Brohl wrote: > > No, we are mainly discussing if we should turn off the JWT functionality > in the default setting and what could be done to make the current > implementation more secure / fail proof. > > > Am 19.01.19 um 16:54 schrieb