Set up alternative authentication for when github OAuth is 'down'

Open
#28 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
elixir, github

Research direction

Start by tracing the current GitHub OAuth flow and how user records are persisted. Define the fallback flow for detecting OAuth failure, sending a one-time email login link, and maintaining the session cookie. Done means users can access their backed-up data during GitHub outages and log out securely.

Written by the indexing model from the issue text.

Description

priority-5

As a gh-backup user
I want to be able to authenticate myself without having to rely on github Oauth running
So that I have secure access to my github data even when github is having technical difficulties.

  • Store user's email addresses in the db
  • Recognise when github OAuth is not working and give user option to authenticate by email
  • Send user an email with a login link, when user clicks on the link they are logged in
  • Store a cookie so that the user is authenticated until they log out

Original Question:
Do we have to use github auth to authorise access to backed up data?
If yes, how do we allow people to access their data when github is down if we can't authenticate them?
If github is down will their authorisation mechanism also be?

Answer:
When someone authenticates when github is up as usual then we will record their email address. Then on an occasion when github is offline we will allow them authenticate using our record of their email. We will send them a one time login link to their email. We will also add a cookie to keep them logged in until they log out.

Dominant language
Elixir
Stars
33
Forks
3
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dwyl/github-backup

All issues in dwyl/github-backup

Similar issues

More Elixir issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.