Ability to query for identity properties without admin rate throttling
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 25/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 领域
- api, authentication
调研方向
查看已记录的 getIdentity 端点以及 /sessions/whoami 的速率限制指南,然后比较它们预期的使用方式和限制。完成标准是确定实时身份属性检索的 API 设计,包括是否支持批量身份查询以及其速率限制应如何运作;该 issue 未指定任何仓库文件或测试。
由索引模型根据 Issue 内容生成。
描述
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
xenodochial-mestorf-alar1uohvl
Describe your problem
We've been using Ory as a single source of truth for user properties, avoiding replication within our application data so as not to increase our exposure to PII. The key properties in our application are user email address and 'display name', both of which are retained solely with Ory.
We have a need to surface this data to our front end, however, in various user listings pages (e.g. listing users who are a member of a team). To achieve this, we've been pulling these properties via our backend calling the https://www.ory.sh/docs/reference/api#tag/identity/operation/getIdentity endpoint
The issue we've encountered is that this solution does not scale, due to rate limiting on the Ory side. Indeed, it would seem this API is not expected to be used for the kind of realtime, user facing use flow we're currently employing it for.
We can address the problem by replicating these properties in our application, but at the cost of maintaining this PII ourselves.
As such, it would be desirable if Ory supported identity property retrieval via an API for such real time use cases such as the one I've described.
Describe your ideal solution
The existence of an API for retrieval of identity properties for any user with rate limiting aligned with the /sessions/whoami (etc) APIs (ref)
Bonus points if the API could accept a set of identities IDs to retrieve properties for
Workarounds or alternatives
Replicating the PII our side, avoiding the need to query Ory for such flows
Version
Ory Network (i.e. your managed, cloud solution)
Additional Context
No response
- 主要语言
- Shell
- 星标
- 96
- 派生
- 8
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
ory/network 的其他 Issue
-
bug
难度 4/5 3-5 天 新手友好度 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking response未关闭bug
难度 4/5 3-5 天 新手友好度 35/100
-
feat
难度 5/5 一周以上 新手友好度 25/100
-
bug
难度 4/5 3-5 天 新手友好度 30/100
-
feat
难度 5/5 一周以上 新手友好度 35/100
相似的 Issue
-
type: bug
难度 2/5 1-3 小时 新手友好度 67/100
catppuccin/kde#152 ·
-
update-request
难度 2/5 1-3 小时 新手友好度 75/100
msys2/MINGW-packages#32008 ·
维护者通常 1 天内回复
-
bot-found bug priority: P3
难度 2/5 1-3 小时 新手友好度 84/100
madenvel/KalinkaPlayer#179 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
documentation
难度 2/5 1-3 小时 新手友好度 72/100