Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
st2-auth-backend-mongodb
Advanced tools
StackStorm authentication backend which reads credentials from a MongoDB collection.
The MongoDB backend reads and authenticates user against data from a MongoDB collection named
users
. The users
collection and the user entries will have to be generated manually.
Entries need to have the following attributes:
field | description |
---|---|
username | User name |
salt | Password salt |
password | SHA256 hash for the salt+password - SHA256(salt+password) |
option | required | default | description |
---|---|---|---|
db_host | no | localhost | Hostname for the MongoDB server |
db_port | no | 27017 | Port for the MongoDB server |
db_name | no | st2auth | Database name in MongoDB |
db_username | no | None | Username for MongoDB login |
db_password | no | None | Password for MongoDB login |
Please refer to the authentication section in the StackStorm documentation for basic setup concept. The following is an example of the auth section in the StackStorm configuration file for the flat-file backend.
[auth]
mode = standalone
backend = mongodb
backend_kwargs = {"db_username": "admin", "db_password": "pass123"}
enable = True
use_ssl = True
cert = /path/to/ssl/cert/file
key = /path/to/ssl/key/file
logging = /path/to/st2auth.logging.conf
api_url = https://myhost.example.com:9101
debug = False
Copyright 2015 StackStorm, Inc.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this work except in compliance with the License. You may obtain a copy of the License in the LICENSE file, or at: http://www.apache.org/licenses/LICENSE-2.0
By contributing you agree that these contributions are your own (or approved by your employer) and you grant a full, complete, irrevocable copyright license to all users and developers of the project, present and future, pursuant to the license of the project.
FAQs
StackStorm authentication backend which reads credentials from a MongoDB collection.
We found that st2-auth-backend-mongodb demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.