-
Notifications
You must be signed in to change notification settings - Fork 67
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Making JupyterLab RTC an opt-in feature #441
Comments
Amazing! To do this,
|
Amazing, indeed... BUT,
I am very worried about the security implications here... Because people excited to try the new stuff will not successfully realize the associated risk and the links will be easily (and publically) shared.
A minimally acceptable security standpoint, IMHO, would be having some sort of minimal authn/authz layer that will prevent users not belonging to the certain Hub to reach out to that server being shared. I acknowledge that, probably, the minimal layer I am asking for is not a trivial amount of work... |
This depends on the token being issued. It could be just as long as the current session. |
OK, that seems to reduce/restrict the potential damage... |
The title is relevant, but the content is outdated. I'll go for a close, expecting another issue to track this already or that its better to start fresh when JupyterHub 4 and JupyterLab 4 are out with some relevant updates. |
Summary
JupyterLab Real Time Collaboration (RTC) is very soon generally available in JupyterLab 3.1 (3.1.0a10 is out now). The access control is non-existent and you simply grant access to remote control your server as if it was you yourself at this point.
User Stories
Acceptance criteria
This enhancement will require significant exploration work, so making decisions on what is an acceptable outcome is a key first step where these acceptance criteria then later can be updated with.
Important information
With
jupyterlab==3.1.0a10
installed, the following startup configuration change will enable link sharing access.With jupyterlab-contrib/jupyterlab-link-share we get a button exposing a token in a link that can be shared. I've opened an issue about this not functioning properly yet with modern versions of JupyterHub etc to my knowledge though, see: jupyterlab-contrib/jupyterlab-link-share#10
Tasks to complete
The text was updated successfully, but these errors were encountered: