crates.io
crates.io copied to clipboard
Limit some actions to only authenticate via token
Currently, all authentication for all routes happens either via a cookie through the browser or via an authentication header from cargo that uses a token. However, actions like publishing a crate and possibly others should only ever happen through cargo-- so it seems like a good idea to me to only authenticate for those actions via an auth header containing a token.
This is probably pretty low priority though.
#1488 fixes this
oh hey cool
FYI #1488 was closed without implementing this.