D 2011-02-21T22:38:38.897 J comment When\susing\snginx\sto\sproxy\sback\sto\sa\sfossil\srepo,\sit's\seasy\sto\seither\suncheck\sonce\sin\sproduction\sor\sleave\sunchecked\sto\sstart.\sNot\sunsolvable,\sbut\sit\swould\sbe\sideal\sto\shave\s"Require\spassword\sfor\slocal\saccess"\schecked\sby\sdefault\sor\sremoved\sall\stogether\sin\sfavor\sof\sthe\sfollowing\sbehavior.\r\n\r\nI\sunderstand\sthat\soption\sis\sthere\sto\sfacilitate\slocal\slogins\svia\s"fs\sui"\sbut\sit\sseems\slike\sa\sbetter\salternative\swould\sbe\sto\smake\s"fs\sui"\sperform\sthe\sfollowing:\r\n\r\n
    \r\n
  1. User\scalls\sfs\sui\sfrom\sthe\scommand\sline
  2. \r\n
  3. fs\sui\sinjects\sa\svalid\sone-time\suse\stoken\sin\sto\sthe\ssessions\stable
  4. \r\n
  5. fs\sui\sthen\scalls\sweb-browser\swith\ssomething\slike\shttp://127.0.0.1:8080/my_repo/auto-login?token=abcdef0123456789abcdef0123456789\swhich\sissues\sthe\suser\sa\slogin\scookie\sand\sremoves\sthe\sone-time\suse\stoken\sfrom\sthe\sdatabase
  6. \r\n
\r\n\r\nThis\sstep\swould\sgo\sa\slong\sways\stowards\sa\s"secure\sby\sdefault"\spolicy\sfor\sFossil. J private_contact 84f59114b7eee7088fd7e2932599c69c9ad0761b J severity Important J status Open J title Default\sdisallow\slocal\slocal\susers J type Feature_Request K 573727d6d93badc681bd957a8e0945b3d053d487 U anonymous Z 33de68eab14175ebd552072c4dd853da