apache / apache/openwhisk-cli

Consider supporting third-party identity providers

Offen
#151 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement
Vorherrschende Sprache
Go
Sterne
109
Forks
98
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

@starpit commented on [Mon Sep 12 2016](https://github.com/apache/incubator-openwhisk/issues/1247)

Without too much effort, OpenWhisk could support third-party identity management providers, such as github, google, etc. The architecture, in sketch, for this would be:

`wsk login --provider github`

The CLI then asks the user to identify with github, and acquires an oauth `code`. The CLI passes this `code` to the backend, which then asks github to exchange it for an `access_token`. The backend next uses this token to acquire the user's immortal profile identifier (e.g. "starpit" for me, on github). Finally, the backend passes this identified user's auth_key back to the CLI client.

The attached gif illustrates an implementation of this, where the backend has been stubbed to only do the relevant bits, and the CLI has been mocked to only do the login bit.

![whisk github cli login](https://cloud.githubusercontent.com/assets/4741620/18455942/294a6a8c-791b-11e6-9dd4-2f91b8f35d61.gif)

---

@starpit commented on [Mon Sep 12 2016](https://github.com/apache/incubator-openwhisk/issues/1247#issuecomment-246546286)

here is my code: https://github.com/starpit/openwhisk-oauth-login

i think only the fake_backend and fake_wsk are throwaways. the two files under lib/ service the client and server sides of this support. written in node.js, sorry, but it's not a huge amount of code to port over to go and scala.

the conf/ needs to be updated, according to the README, to install your own client_id and client_secrets for the identity providers.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Überprüfe das verlinkte openwhisk-oauth-login-Projekt und dessen README, insbesondere die Dateien in lib/ und conf/, um den vorgeschlagenen Client- und Serverablauf zu verstehen. Untersuche anschließend den Login-Einstiegspunkt von openwhisk-cli und die vorhandene Konfiguration; als abgeschlossen gilt dies, wenn ein dokumentierter, funktionierender provider-basierter Login-Ablauf mit Backend-Token-Austausch und Unterstützung für das Zurückgeben von auth_key vorhanden ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
go, node.js, scala
Bereich
authentication, backend-api-design, cli
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.