ga4gh / ga4gh/task-execution-schemas

Authentication directly in the OpenAPI specification

Open
#151 1 comment 0 reactions 0 assignees View on GitHub
Due: Sep
Dominant language
No language data
Stars
95
Forks
32
PR merge metrics
No merged PRs in 30d

Description

I am opening the issue to start/resume a discussion around authentication requirement for Cloud WS APIs, in this case TES.
* Should TES specification contain authentication requirement (should all compatible implementations support authentication)?
* Which methods should be supported?
* If authentication is a requirement, can it be described directly using [OpenAPI] (https://swagger.io/docs/specification/authentication/) `securitySchemes`?
* How to ensure compatibility with emerging GA4GH standards such as GA4GH Passports?

Currently TES specification suggests:
`If authentication is required, we recommend that TES implementations use an OAuth2 bearer token, although they can choose other mechanisms if appropriate.`
We know of implementations supporting either OAuth2 bearer tokens or Basic Auth.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the current TES authentication wording and the linked OpenAPI authentication guidance. Compare the proposed OAuth2 bearer-token and Basic Auth approaches, and consider compatibility with GA4GH Passports; done requires a resolved authentication policy and an agreed specification change.

Written by the indexing model from the issue text.

Assessment

Tech stack
openapi
Domain
api, authentication
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.