ga4gh / ga4gh/task-execution-schemas
Authentication directly in the OpenAPI specification
- Dominant language
- No language data
- Stars
- 95
- Forks
- 32
- PR merge metrics
- No merged PRs in 30d
Description
I am opening the issue to start/resume a discussion around authentication requirement for Cloud WS APIs, in this case TES.
* Should TES specification contain authentication requirement (should all compatible implementations support authentication)?
* Which methods should be supported?
* If authentication is a requirement, can it be described directly using [OpenAPI] (https://swagger.io/docs/specification/authentication/) `securitySchemes`?
* How to ensure compatibility with emerging GA4GH standards such as GA4GH Passports?
Currently TES specification suggests:
`If authentication is required, we recommend that TES implementations use an OAuth2 bearer token, although they can choose other mechanisms if appropriate.`
We know of implementations supporting either OAuth2 bearer tokens or Basic Auth.
Contributor guide
Research direction
Start by reviewing the current TES authentication wording and the linked OpenAPI authentication guidance. Compare the proposed OAuth2 bearer-token and Basic Auth approaches, and consider compatibility with GA4GH Passports; done requires a resolved authentication policy and an agreed specification change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- openapi
- Domain
- api, authentication
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100