microsoft / microsoft/azure-devops-python-api

Authentication through Personal Access Token creates organisational coupling

Ouverte
#500 3 commentaires 2 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Langage dominant
Python
Étoiles
684
Forks
218
Merge moyen
8 j 10 h
PR mergées (30 j)
1

Description

Currently, the only documented way to use this library is to authenticate with a Personal Access Token.

This seems wrong, as:

  • From what I know about them, Personal Access Tokens are associated to human accounts
    This means an application access to an Azure DevOps instance is tightly coupled to the existence of a human person in an organisation, which means applications access will break depending on other life cycles.
  • Personal Access Token also require an expiration date, meaning applications access will break regularly, forcing some manual (human) extra credentials management on top of, and separate from, the one associated with the parent account.

Is there a plan to support other kinds of authentication scheme with Azure DevOps (Server)?

One could think of an OAuth2 process, for instance, allowing different flows:

  • H2M, much like what is achieved through PAT, without any extra (token, on top of account), manual, token lifecycle management
  • M2M which would allow managing applications-specific secrets

Both flow isolate authentication of the application from any other organisational resource, and allow delegation of authorisation and grants lifecycle to a dedicated, potentially automated third-party.

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez par examiner l’authentification documentée de la bibliothèque par Personal Access Token ainsi que les flux d’authentification OAuth2 ou d’application pris en charge par Azure DevOps Server. Comparez les exigences de H2M et de M2M, puis définissez le flux pris en charge, le cycle de vie des identifiants et la documentation ou les tests nécessaires pour démontrer l’achèvement.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
azure, python
Domaine
api, authentication, cloud
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.