Add first party support for Github App
Nessuno ha ancora preso questa issue.
- Lingua principale
- Go
- Stelle
- 11.3k
- Fork
- 2.5k
- Merge medio
- 1g 20h
- PR unite (30g)
- 53
Descrizione
Many of the apis requires to be invoked as Github App, eg. https://docs.github.com/en/rest/checks/runs?apiVersion=2022-11-28. And currently we need to use third-party packages like ghinstallation to do so.
However, this is not the full story. When creating a Github App, it involves many different kinds of creds:
And we need to use different cred to call different APIs. For now, the only way to do so is to create many different github.Clients, each holding a different credential.
And we need to do this with extra care, as all these token are short-lived, and need to be cached/refreshed periodically. Which means, blindly creating those clients will cause lots of rate limiting issues.
For instance, to use github.ChecksService, we need:
- Auth as Github App itself by creating a JWT with app's private key, to call
github.AppServiceCreateInstallationToken - Once we have the token, we can auth as app installation, then calling
github.ChecksService
Which requires 2 github.Clients in total.
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Inizia esaminando github.Client, AppServiceCreateInstallationToken e ChecksService, insieme ai tre flussi di autenticazione di GitHub collegati nell’issue. Definisci il supporto first-party necessario per le credenziali dell’app, dell’installazione e dell’utente, inclusi il riutilizzo sicuro e il rinnovo dei token di breve durata tra le chiamate API.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- github, go
- Ambito
- api, authentication
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Ferma
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 30/100