Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    Feed not requiring APIKey to push package

    Scheduled Pinned Locked Moved Support
    apiauthenticationpermissionsproget
    8 Posts 1 Posters 37 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? This user is from outside of this forum
      Guest
      last edited by

      I have a feed setup with an APIKey and Anonymous is allowed "Add_Package", as described here: https://inedo.com/support/kb/1112/api-keys-in-proget

      Without logging in, I am able to "Add Package" via the Web UI using the "Upload from Disk" option.

      If I select the "Pull from another repository", it prompts me to log in.

      If I do it via nuget.exe from the command line, it requires either authentication or the API key.

      Any assistance would be appreciated
      Thanks

      Product: ProGet
      Version: 4.0.9

      1 Reply Last reply Reply Quote 0
      • ? This user is from outside of this forum
        Guest
        last edited by

        Make sure to set up the API Key on the feed page, not in the Admin > Advanced Settings. The latter is used to interact with ProGet, whereas the feed's API key is only used for the feed.

        Once a Feed API Key is specified...

        Users must authenticate and have sufficient privileges to push a package to the Feed. Once the privileges are verified, the supplied API Key is checked to verify that it matches the custom key specified on the Feed Overview page. To enable anyone to push packages so long as the API Key is correct, grant the Feeds_AddPackage privilege to the Anonymous User

        1 Reply Last reply Reply Quote 0
        • ? This user is from outside of this forum
          Guest
          last edited by

          Yes, the API key is defined on the feed. I wasn't even aware of the API Key in the Advanced Settings screen, which is undefined.

          1 Reply Last reply Reply Quote 0
          • ? This user is from outside of this forum
            Guest
            last edited by

            I'm not sure I understand the issue then? You wrote...

            If I do it via nuget.exe from the command line, it requires either authentication or the API key.

            So, if you configured an API Key for the feed, then you're going to still have to specify it when you push a package.. What behavior are you expecting?

            1 Reply Last reply Reply Quote 0
            • ? This user is from outside of this forum
              Guest
              last edited by

              "Without logging in, I am able to "Add Package" via the Web UI using the "Upload from Disk" option"

              This is the problem. The command line is working as expected.

              1 Reply Last reply Reply Quote 0
              • ? This user is from outside of this forum
                Guest
                last edited by

                I see; that's the expected behavior because you've granted "Anonymous" permissions to do those things. The API key is only used by the API.

                1 Reply Last reply Reply Quote 0
                • ? This user is from outside of this forum
                  Guest
                  last edited by

                  OK, I guess I can understand that, but then why is this true?

                  If I select the "Pull from another repository", it prompts me to log in.

                  If this is truly functioning as designed/expected, a warning on your support KB page about this would seem appropriate. It seems unlikely that someone setting it up this way actually wants this behavior, and without testing every path to push a package, would have no idea.

                  1 Reply Last reply Reply Quote 0
                  • ? This user is from outside of this forum
                    Guest
                    last edited by

                    The "Pull from Another Repository" actually requires the Feeds_PullPackage privilege; so make sure to grant anonymous that as well. Then it should work as expected!

                    1 Reply Last reply Reply Quote 0

                    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                    With your input, this post could be even better 💗

                    Register Login
                    • 1 / 1
                    • First post
                      Last post
                    Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation