HelloZeroNet / HelloZeroNet/ZeroNet

Ability to login via Multiuser plugin easily over Websocket

Open
#1,902 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
18.8k
Forks
2.3k
PR merge metrics
No merged PRs in 30d

Description

Currently the Multiuser plugin's API is quite browser-specific. From reverse-engineering how it works, I've discovered that to login via Multiuser you must:

* you login by calling "userLoginForm" and receiving a prompt containing HTML
* ignore the HTML and respond to the prompt with a private key
* the plugin converts this private key to a master_seed and a master_address
* the plugin creates some javascript to load the master_address into your browser's cookies
* it sends that javascript back to you
* now on subsequent requests you're supposed to send the master_address as a cookie (called "master_address")

This isn't too complicated (though extracting the master_address from the returned JS is a little horrible), but the real problem comes in when some WebSocket clients don't support setting cookies.

Is it possible to have a different method of authenticating one's requests to Multiuser? I agree cookies are quite elegant, and keep the request payload clean, but it makes things tricky for non-browser clients.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.