Persistent API keys
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 25/100
- Issue 類型
- 功能
- 描述清晰度
- 需要釐清
- 活躍度
- 停滯
- 領域
- api, authentication
研究方向
Issue 中未識別出任何 repository 檔案、測試或入口點;從描述中連結的 fastapi-users 驗證設定開始,追蹤現有的 JWT 登入流程。定義持久化金鑰模型、撤銷、可選的到期時間和 scopes,以及交換流程,使短期 JWT 的續期同時適用於互動式和非互動式登入。
由索引模型根據 Issue 內容生成。
描述
At the moment, a user can login and get a JWT token. These tokens aren't stored in the database and have a baked-in expiry time. They're used for temporary sessions, typically by web browsers. This is fine and we'll definitely need this kind of tokens, but it's not designed to be used for automation tools that use the API continuously such as pipeline services.
In addition to the JWT, we should create another kind of tokens which we might call "API access keys". These would be stored in the database and could be revoked by the user. They may also have an expiry date and scopes to fine-tune the operations that can be performed with them. This is how most web APIs work, with persistent credentials for this kind of use-case. I don't think fastapi-users can support both, but it can support one or the other:
https://fastapi-users.github.io/fastapi-users/10.0/configuration/authentication/
In our particular case, I would like to suggest that we use the persistent API keys as a way to get a temporary JWT token. So a user can interactively login with a username / password interactive form or non-interactively by sending an access token. Then a short-lived JWT token is generated (say, valid for 1h) and when it expires a new one needs to be generated.
- 主要語言
- Python
- 星號
- 10
- 分支
- 21
- 平均合併
- 22 分鐘
- 30 天內合併 PR
- 1
環境準備
- 提供 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 沒有貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
kernelci/kernelci-api 的其他 Issue
-
難度 4/5 3-5 天 新手友好度 45/100
kernelci/kernelci-api#706 ·
-
Components/Maestro/API/Local instance says GET /latest/ should return some JSON, but it doesn't可能重新可做 關聯的 PR 已關閉且未合併。 未關閉documentation
難度 3/5 1-2 天 新手友好度 35/100
kernelci/kernelci-api#632 · 1 則留言 ·
-
難度 5/5 一週以上 新手友好度 20/100
kernelci/kernelci-api#629 ·
-
難度 4/5 3-5 天 新手友好度 35/100
kernelci/kernelci-api#608 ·
-
難度 3/5 1-2 天 新手友好度 35/100
kernelci/kernelci-api#597 · 2 則留言 ·
查看 kernelci/kernelci-api 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 82/100
RedHatQE/mtv-api-tests#721 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 84/100
維護者通常 1 天內回覆
-
難度 1/5 1-3 小時 新手友好度 85/100
pytest-dev/pluggy#757 ·
維護者通常 1 天內回覆
-
難度 1/5 1-3 小時 新手友好度 85/100
NousResearch/hermes-agent#134960 ·
維護者通常 1 天內回覆
-
HTML backend: `<br>` leaks the internal sentinel U+E000 into list items, headings and captions可能已有人在做 @morten-lagabote 今天認領。 未關閉
難度 2/5 1-3 小時 新手友好度 67/100
docling-project/docling#4671 ·
維護者通常 1 天內回覆