feature: support both WebID-TLS and Solid-OIDC authentication simultaneously
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- javascript, node.js
- Ambito
- authentication, backend
Direzione di ricerca
Inizia da lib/create-app.mjs:335-339, quindi esamina i punti di ingresso dell’inizializzazione di API.authn.oidc e API.authn.tls. Verifica come ogni handler chiama next() quando le credenziali sono assenti e definisci il completamento come l’autenticazione dei client WebID-TLS e Solid-OIDC sullo stesso server.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
Currently NSS only supports one authentication method at a time (--auth tls OR --auth oidc). It would be valuable to support both simultaneously.
Current Behavior
// lib/create-app.mjs:335-339
const auth = argv.forceUser ? 'forceUser' : argv.auth
if (!(auth in API.authn)) {
throw new Error(`Unsupported authentication scheme: ${auth}`)
}
await API.authn[auth].initialize(app, argv) // Only ONE method initialized
Proposed Behavior
Initialize both auth handlers and let them chain naturally:
async function initAuthentication(app, argv) {
// Initialize both handlers
await API.authn.oidc.initialize(app, argv)
await API.authn.tls.initialize(app, argv)
}
The handlers already call next() when they don't find their credentials, so they'd naturally fall through to the next method.
Benefits
- Flexibility - Different clients can use different auth methods against the same server
- Migration path - Users can transition gradually between auth methods
- Spec compliance - Solid doesn't mandate one auth method over another
- Client compatibility - Legacy TLS clients and modern OIDC clients work together
Implementation
The change is minimal:
- Remove the either/or logic in
initAuthentication() - Initialize both handlers (or make it configurable:
--auth oidc,tls) - Auth chain: OIDC → TLS → anonymous
Prior Art
JavaScriptSolidServer (JSS) already supports this - it tries auth methods in sequence:
- Solid-OIDC (DPoP tokens)
- WebID-TLS (client certificates)
- Bearer tokens
Works well and provides maximum flexibility.
- Lingua principale
- JavaScript
- Stelle
- 1.8k
- Fork
- 308
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di nodeSolidServer/node-solid-server
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
nodeSolidServer/node-solid-server#1848 · 2 commenti · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
nodeSolidServer/node-solid-server#1841 · 2 commenti ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
nodeSolidServer/node-solid-server#1147 ·
-
remove bootstrap dependency Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
nodeSolidServer/node-solid-server#1867 ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 45/100
nodeSolidServer/node-solid-server#1853 ·
Tutte le issue di nodeSolidServer/node-solid-server
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
avniproject/avni-client#2135 ·
-
automated broken-link
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
-
agent/security hive/hosted-available-lke648397-260827-5n31 security
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
babalae/bettergi-scripts-list#3674 ·
-
A-Release-Notes C-Editing D-Modest S-Ready-For-Implementation
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
bevyengine/bevy-website#2595 ·