Hi, I'm testing out the basic auth feature, using ...
# pact-broker
a
Hi, I'm testing out the basic auth feature, using the
pactfoundation/pact-broker
docker image. I've supplied credentials to:
PACT_BROKER_BASIC_AUTH_USERNAME
PACT_BROKER_BASIC_AUTH_PASSWORD
and I have also set
PACT_BROKER_ALLOW_PUBLIC_READ=true
The credentials appear to work fine when making calls like:
create-or-update-pacticipant
. But I also wanted to test what happens if we try to delete a pacticpant (or even a pact) using the pact broker API (Hal) browser. And the creds don't work. I used the same credentials specified in the ENV vars above. Are those the creds I should be using? Or something else? (I also tried my pact broker admin user and standard user, with no success). There doesn't seem to be any mention of what creds to use in the documentation, when using the UI and when BASIC_AUTH variables have been supplied. Appreciate any help and advice. Thanks, Alan
m
(I also tried my pact broker admin user and standard user, with no success).
what are these, exactly?
The Pact Broker has two sets of credentials, the ones above an the “read-only” variants (https://docs.pact.io/pact_broker/configuration/settings#basic_auth_read_only_username)
The basic auth credentials should allow you to perform any action
a
Apologies, I should have said postgres users, admin and "pactbrokeruser". Credentials supplied at container start-up with Environment switches...
-e PACT_BROKER_BASIC_AUTH_USERNAME=pactwriter -e PACT_BROKER_BASIC_AUTH_PASSWORD=mywritepassword
The creds do not work through the web UI.
The full command that I am using....
Copy code
sudo docker run --name pactbroker --restart unless-stopped --link pactbroker-db:postgres -e PACT_BROKER_DATABASE_USERNAME=pactbrokeruser -e PACT_BROKER_DATABASE_PASSWORD=TheUserPassword -e PACT_BROKER_DATABASE_HOST=postgres -e PACT_BROKER_DATABASE_NAME=pactbroker -e PACT_BROKER_BASIC_AUTH_USERNAME=pactwriter -e PACT_BROKER_BASIC_AUTH_PASSWORD=mywritepassword -e PACT_BROKER_ALLOW_PUBLIC_READ=true -d  -p 9292:9292 pactfoundation/pact-broker
Then do something like this...[see pics] Delete -> make request You then get prompted for creds, try the
pactwriter
credentials. Result, returned to the logon dialog. Please let me know if I'm doing this incorrectly.
m
hmm, it should be
pactwriter
and
mywritepassword
a
Any chance you could try and reproduce?
m
can you provide a series of CLI commands I can run to test? (the command above links a database). I’d suggest: 1. a docker compose file I can start 2. an API call I can test from the CLI to show the problem (create pacticipant, issue
DELETE
etc.) 3. If the API call works, then a series of steps in the UI
a
Sure
thankyou 1
Hi. Sorry for the delay on this. Work is very busy. I am not using Docker Compose (at the moment) to run this test. It was a simple local setup, created by running the Running Postgresql via Docker (from here: https://github.com/pact-foundation/pact-broker-docker/blob/master/POSTGRESQL.md#running-postgresql-via-docker ) At step 3. in the steps above, I adapted the command to run the Pactbroker to this:-
Copy code
sudo docker run --name pactbroker --restart unless-stopped --link pactbroker-db:postgres -e PACT_BROKER_DATABASE_USERNAME=pactbrokeruser -e PACT_BROKER_DATABASE_PASSWORD=TheUserPassword -e PACT_BROKER_DATABASE_HOST=postgres -e PACT_BROKER_DATABASE_NAME=pactbroker -e PACT_BROKER_BASIC_AUTH_USERNAME=pactwriter -e PACT_BROKER_BASIC_AUTH_PASSWORD=mywritepassword -e PACT_BROKER_ALLOW_PUBLIC_READ=true -d  -p 9292:9292 pactfoundation/pact-broker
As you can see a very simple setup. I've not performed any direct API calls. I've tested by calling
docker run --rm pactfoundation/pact-cli pact-broker...
type commands. Which are successful when supplying the credentials. So for example I used the type of command above to create a dummy pacticipant. Then using the UI, I went to the pacticipant that I had just created, and performed a Non-Get request (see pic). You then get prompted for credentials, and authentication seems fail (no error shown). You just get returned to the credentials prompt.
@Matt (pactflow.io / pact-js / pact-go) Hi. Just wondered if you'd managed to find some time to reproduce this? Could really do with your advice. I really need to lock our broker down, as some individuals are mistakenly pushing to the central broker, rather than their "local test" broker instance. I feel it could be causing problems. Many Thanks
m
Seems to work as expected for me
a
🤔 Wonder what I'm getting wrong.
m
Have you tried another browser / incognito just in case?
a
Hi. I got to the bottom of this. There must have been something wrong with the password I'd set. So, must have been my error. But thanks for your time and help.
👍 1
m
No probs! Glad to hear it’s resolved
browsers do funny things with basic auth, as far as I can tell, there is little visibility into it also