dwyl / dwyl/github-backup

Set up alternative authentication for when github OAuth is 'down'

Open
#28 1 comment 0 reactions 0 assignees View on GitHub
priority-5
Dominant language
Elixir
Stars
33
Forks
3
PR merge metrics
No merged PRs in 30d

Description

As a gh-backup user
I want to be able to authenticate myself without having to rely on github Oauth running
So that I have secure access to my github data even when github is having technical difficulties.

- [ ] Store user's email addresses in the db
- [ ] Recognise when github OAuth is not working and give user option to authenticate by email
- [ ] Send user an email with a login link, when user clicks on the link they are logged in
- [ ] Store a cookie so that the user is authenticated until they log out

----------------
**Original Question:**
Do we have to use github auth to authorise access to backed up data?
If yes, how do we allow people to access their data when github is down if we can't authenticate them?
If github is down will their authorisation mechanism also be?

**Answer:**
When someone authenticates when github is up as usual then we will record their email address. Then on an occasion when github is offline we will allow them authenticate using our record of their email. We will send them a one time login link to their email. We will also add a cookie to keep them logged in until they log out.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.