Overview
dsh-auth-gate
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
The short list; the full version, including the mechanisms and the ADRs behind them, is in `docs/deployed/known-limitations.md`. - Disabling a user only stops **new** logins; sessions already issued are revoked by the periodic sweep (`revokeSweepMs`, 5 s by default - with `0` they stay valid until they expire). - Login rate limiting and the TOTP replay guard reset when the server restarts. - Behind a reverse proxy, set `clientIpHeader` (and `trustedProxyCidrs`): otherwise all clients share one lockout bucket, and login plus the self-service change each have their own, so both are affected. - A password change reports success even if revoking the old sessions fails; the failure is logged at error level and the old cookie stays valid until its session TTL. - The plugin protects dsh's web surface only. Keep the OS user and the config files private.
