[GitHub] [apisix] moonming commented on a change in pull request #2230: bug: removed default access token for Admin API

2020-09-15 Thread GitBox


moonming commented on a change in pull request #2230:
URL: https://github.com/apache/apisix/pull/2230#discussion_r488454473



##
File path: bin/apisix
##
@@ -643,6 +643,34 @@ local function read_yaml_conf()
 merge_conf(default_conf, user_conf)
 end
 
+-- check the Admin API token
+if default_conf.apisix.enable_admin then
+local help = [[
+ERROR: missing valid apisix.admin_key
+
+You can call `]] .. arg[0] .. [[ gen_admin_key` to generate a new Admin API 
key or
+manually update the `conf/config.yaml` file.
+]]
+if type(default_conf.apisix.admin_key) ~= "table" or
+   #default_conf.apisix.admin_key == 0
+then
+io.stderr:write(help, "\n")
+os.exit(1)
+end
+
+for _, admin in ipairs(default_conf.apisix.admin_key) do
+if type(admin.key) == "table" then
+admin.key = ""
+else
+admin.key = tostring(admin.key)
+end
+
+if admin.key == "" or admin.key:gsub("*", "") == "" then

Review comment:
   `*` is invalid, which is too shadowy





This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org




[GitHub] [apisix] moonming commented on a change in pull request #2230: bug: removed default access token for Admin API

2020-09-14 Thread GitBox


moonming commented on a change in pull request #2230:
URL: https://github.com/apache/apisix/pull/2230#discussion_r488430805



##
File path: FAQ.md
##
@@ -80,7 +80,7 @@ An example, `foo.com/product/index.html?id=204&page=2`, gray 
release based on `i
 
 here is the way:
 ```shell
-curl -i http://127.0.0.1:9080/apisix/admin/routes/1 -H 'X-API-KEY: 
edd1c9f034335f136f87ad84b625c8f1' -X PUT -d '
+curl -i http://127.0.0.1:9080/apisix/admin/routes/1 -H 'X-API-KEY: **' -X 
PUT -d '

Review comment:
   `**` is not a good hint for user.





This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org