4 ms·
A true hacker! Though not sure what to think about the security of that headless browser setup
by orzig 4y ago
A true hacker! Though not sure what to think about the security of that headless browser setup
- iLemming 4y agoI made sure that the credentials are stored in GPG encrypted file and could only be decrypted on my machine. github.com/agzam/jira-okta-puppet/blob/master/src/jira_auth/auth.cljs Basically, it was no different if I'd have to login manually, then open browser's dev-tools, and copy&paste the token. Arguably, my automated approach made it slightly more secure, since there's no clipboard involved. It was stupid, I should've figured out the proper way of authenticating, but something was missing, I either needed to ask admin to give me OAuth access, or some other bullcrap. Well, you know how the saying goes, right? "It ain't stupid if it works".