coder / coder/coder-jetbrains-toolbox

Secure storage of sensitive keys via OS Keyring

Open
#267 1 comment 0 reactions 1 assignee Claimed by @fioan89 View on GitHub
Feature jetbrains-toolbox
Dominant language
Kotlin
Stars
23
Forks
7
Avg merge
3d 12h
Merged PRs (30d)
10

Description

For smooth login experiences we should persist in in the OS credential manager (Keychain on macOS, Windows Credential Manager, libsecret/keyring on Linux) the following:
- client id
- client secret
- refresh token
Coder server implements Dynamic Client Registration (RFC 7591), each installation registers itself and gets its own unique client_id and client_secret, that can be stored in the OS keyring.
- CLI should also use keyring to securely persist access token in the OS Keyring

Other notes:
- access token, discard on exit
- access token expiry, needed only for the duration of the session
- code verifier, delete after token exchange
- state, delete after redirect verification

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.