Disable certain functionalities in RemoteOAuth2Mixin
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 25/100
- Issue 类型
- 重构
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- python
- 领域
- api, authentication, security
调研方向
先阅读 RemoteOAuth2Mixin 和 DeveloperTokenAuth,然后审查 issue #173 中的通用基类提案。确定是否应禁用或移除 revoke() 和列出的构造函数选项,并定义 2.0.0 版本发布时预期的破坏性变更行为。
由索引模型根据 Issue 内容生成。
描述
When using RemoteOAuth2Mixin, all /token calls are delegated to another process or server. Thus:
- The
client_idandclient_secretshouldn't be required. In fact, they perhaps shouldn't even be allowed to be passed. Clients that need to do remote auth should be discouraged from having any of their credentials hard-coded, especially since they aren't even needed. store_tokensshould perhaps be disallowed. Since the tokens are owned by the remote process, it should be in control of where its tokens go. If a client needs to restart, it should get its tokens from the remote process/server, not from its own token store.box_device_idandbox_device_nameare useless if we're not making/tokencalls.refresh_tokenshould never be available to the client, so it shouldn't be possible to pass this.
Also, since the remote process/server owns the tokens, we should possibly disable revoke(). If we do that, then:
- We definitely don't need
client_idandclient_secretanymore, since they would never be used. - For the same reason, we also don't need
network_layeranymore. - We might not need
refresh_lockanymore. Presumably, the remote server can handle its own locking, without the clients needing to coordinate.
revoke could be made to pass (DeveloperTokenAuth does this) or raise, and the unneeded constructor arguments can be passed as None to the super-class, so that TypeError is raised if a user tries passing any of them.
Alternatively, factor this into #173, and create a common base-class that doesn't have any of these functionalities.
This would be a breaking change, so consider this for 2.0.0.
- 主要语言
- Python
- 星标
- 460
- 派生
- 224
- 平均合并
- 11 小时 29 分钟
- 30 天内合并 PR
- 20
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
box/box-python-sdk 的其他 Issue
-
enhancement
难度 2/5 1-3 小时 新手友好度 68/100
box/box-python-sdk#196 ·
维护者通常 1 天内回复
-
JTI claim value is not getting regenerated if API calls fails due to rate limit可能重新可做 @mwwoda 于 288 天前认领,目前没有进行中的 PR。 未关闭bug enhancement
box/box-python-sdk#1314 · 6 条评论 · 已指派 5 人 ·
维护者通常 1 天内回复
-
Missing py.typed marker in box_sdk_gen causes mypy import-untyped error可能重新可做 @mwwoda 于 392 天前认领,目前没有进行中的 PR。 未关闭enhancement
box/box-python-sdk#1154 · 5 条评论 · 已指派 5 人 ·
维护者通常 1 天内回复
-
enhancement
难度 5/5 一周以上 新手友好度 25/100
box/box-python-sdk#1155 · 1 条评论 · 4 个 reaction ·
维护者通常 1 天内回复
-
Implement `__eq__` for CreateFolderParent class可能重新可做 @mwwoda 于 655 天前认领,目前没有进行中的 PR。 未关闭enhancement
box/box-python-sdk#1157 · 1 条评论 · 已指派 6 人 ·
维护者通常 1 天内回复
查看 box/box-python-sdk 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 92/100
raullenchai/Rapid-MLX#4042 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
LearningCircuit/local-deep-research#7067 ·
维护者通常 1 天内回复
-
#bug
难度 1/5 1 小时以内 新手友好度 92/100
apache/superset#44923 · 1 条评论 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
lawndoc/stack-back#123 ·