Improving integration with keyring and pip authentication. #11827
Labels
C: keyring
Related to pip's keyring integration
S: needs triage
Issues/PRs that need to be triaged
type: feature request
Request for a new feature
What's the problem this feature will solve?
In the current implementation of integration between keyring and pip authentication we could ask username of keyring user and use this method of authentication as 401 fallback.
I would like to improve the integration by:
These changes improve integration with keyring and help private companies to block anonymous access to their internal PyPi reposiotires by setting up keyring authentification on their dev machines and CI clusters.
Describe the solution you'd like
Instead of describing the solution I already prepared the fix:
#11823
I didn't create new test cases for my logic because first I would like to here your oppinion about this change and only after that add unittest/integration tests + update docs.
Alternative Solutions
As an alternative solution we can use:
But in this case people should store unencrypted passwords/tokens in their home directories.
=> user processes will be able to read passwords/tokens => some viruses could steal passwords/tokens
There are the same problem
Keyring allows storage encryption on dev devices and CI machines.
Additional context
I don't have any additional context.
Code of Conduct
The text was updated successfully, but these errors were encountered: