I wouldn't want HR in charge of my secrets management in any way shape or form.
Happy to have a level of group synchronisation out of HR's systems, but certainly would not give them the ability to manage the high-power users.
HN user
I wouldn't want HR in charge of my secrets management in any way shape or form.
Happy to have a level of group synchronisation out of HR's systems, but certainly would not give them the ability to manage the high-power users.
Similar to https://openfeature.dev/ ?
There is a discussion about the lack of support here -
(https://github.com/github-community/community/discussions/77... - released by end of June)
It's in the DoJ PDF - https://www.justice.gov/opa/press-release/file/1440946/downl...
If you freeze it for 24 hours it will kill them off. Can be a good idea to do that when it comes into the house anyway as they might be in there already.
Easy enough to separate them out of the rice after freezing too.
If you haven't, check out GEERS - https://www.ag.gov.au/industrial-relations/general-employee-...
The limitation with the approach (of HTTP=>HTTPS redirects) is that your average coffee-shop-wifi-user may not notice if their connection does not upgrade to HTTPS due to malicious interception of their connections.
With HSTS, once they've connected to the server over HTTPS once (e.g. at home), every connection from that browser will be immediately upgraded to HTTPS before even trying HTTP.
Your suggestion is valid - as HSTS is only delivered over HTTPS - and the upgrade is still required the first time.
See Firesheep for an example of how HTTP can be intercepted - https://en.wikipedia.org/wiki/Firesheep