Persistent API keys
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 25/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Necesita aclaración
- Estado de actividad
- Estancado
- Área
- api, authentication
Línea de trabajo
En el issue no se identifican archivos del repositorio, pruebas ni puntos de entrada; comienza con la configuración de autenticación de fastapi-users enlazada en la descripción y sigue el flujo de inicio de sesión JWT existente. Define el modelo de claves persistentes, la revocación, la expiración y los scopes opcionales, y el flujo de intercambio, haciendo que la renovación de JWT de corta duración funcione tanto para el inicio de sesión interactivo como para el no interactivo.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
At the moment, a user can login and get a JWT token. These tokens aren't stored in the database and have a baked-in expiry time. They're used for temporary sessions, typically by web browsers. This is fine and we'll definitely need this kind of tokens, but it's not designed to be used for automation tools that use the API continuously such as pipeline services.
In addition to the JWT, we should create another kind of tokens which we might call "API access keys". These would be stored in the database and could be revoked by the user. They may also have an expiry date and scopes to fine-tune the operations that can be performed with them. This is how most web APIs work, with persistent credentials for this kind of use-case. I don't think fastapi-users can support both, but it can support one or the other:
https://fastapi-users.github.io/fastapi-users/10.0/configuration/authentication/
In our particular case, I would like to suggest that we use the persistent API keys as a way to get a temporary JWT token. So a user can interactively login with a username / password interactive form or non-interactively by sending an access token. Then a short-lived JWT token is generated (say, valid for 1h) and when it expires a new one needs to be generated.
- Lenguaje dominante
- Python
- Estrellas
- 10
- Forks
- 21
- Merge medio
- 22 min
- PR fusionados (30 d)
- 1
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Sin plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de kernelci/kernelci-api
-
Optimize node collection indexesAbierto
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
kernelci/kernelci-api#706 ·
-
Components/Maestro/API/Local instance says GET /latest/ should return some JSON, but it doesn'tQuizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abiertodocumentation
Dificultad 3/5 1-2 días Aptitud para principiantes 35/100
kernelci/kernelci-api#632 · 1 comentario ·
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 20/100
kernelci/kernelci-api#629 ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
kernelci/kernelci-api#608 ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 35/100
kernelci/kernelci-api#597 · 2 comentarios ·
Todos los issues de kernelci/kernelci-api
Issues similares
-
changelog investigate
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
ramnes/notion-sdk-py#409 ·
-
good first issue help wanted
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
lindicaphxag-tech/kaggle#28 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
BSData/horus-heresy-3rd-edition#3211 ·
Los mantenedores suelen responder en 1 día
-
bug needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
Unreachable-proxy mount test depends on fixed port 9999Posiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertobug tests
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día