Does disabling token authentication and setting a password enforce cookie‑based login for Jupyter Notebook endpoints?
0 reputation · 29 Aug 2021, 03:17 UTC
Goal: Configure a local Jupyter Notebook server for integration tests that avoids using real production credentials while still requiring some form of authentication, and determine how the notebook trust system behaves under these settings.
Uncertainty: When the token is disabled via --NotebookApp.token='', the server relies on a password hash or allows anonymous access; it is not fully documented whether cookie‑based authentication is enforced for all endpoints (including the REST API and static files) and whether an untrusted notebook’s HTML/JavaScript output can execute regardless of the authentication state.
Specific questions:
- Does setting a password hash while the token is empty enforce cookie‑based authentication for every HTTP endpoint served by the notebook server?
- Can an untrusted notebook containing active HTML/JavaScript output execute when opened via the notebook UI or API if token authentication is disabled?
- Is there a reliable way to simulate authenticated requests in integration tests without exposing the server to external network access?