kernelci / kernelci/kernelci-api

Persistent API keys

Ouverte
#414 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
Python
Étoiles
10
Forks
21
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

At the moment, a user can login and get a JWT token. These tokens aren't stored in the database and have a baked-in expiry time. They're used for temporary sessions, typically by web browsers. This is fine and we'll definitely need this kind of tokens, but it's not designed to be used for automation tools that use the API continuously such as pipeline services.

In addition to the JWT, we should create another kind of tokens which we might call "API access keys". These would be stored in the database and could be revoked by the user. They may also have an expiry date and scopes to fine-tune the operations that can be performed with them. This is how most web APIs work, with persistent credentials for this kind of use-case. I don't think `fastapi-users` can support both, but it can support one or the other:

https://fastapi-users.github.io/fastapi-users/10.0/configuration/authentication/

In our particular case, I would like to suggest that we use the persistent API keys as a way to get a temporary JWT token. So a user can interactively login with a username / password interactive form or non-interactively by sending an access token. Then a short-lived JWT token is generated (say, valid for 1h) and when it expires a new one needs to be generated.

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

No repository files, tests, or entry points are identified in the issue; start with the fastapi-users authentication configuration linked in the description and trace the existing JWT login flow. Define the persistent key model, revocation, optional expiry and scopes, and exchange flow, with short-lived JWT renewal working for both interactive and non-interactive login.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
fastapi, python
Domaine
api, authentication
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.