Open
Conversation
Contributor
|
Hi @StefanIvanciuc. Thanks for this patch! It has a lot of good ideas, but I think we want to implement this functionality in a different way. We'd like keep the OAuth flow out of the open source REST API. Because this code is AGPL license, we need to have a clearly defined interface that doesn't directly link a 3rd party developer's codebase. Also, given that the API doesn't have any security, it's unwise to open the OAuth flow to public internet (which is required for the Google callback). I haven't had the time to fully implement this, but I'd like to add a few endpoints under
Also, please sign the Contributor License Agreement so we can merge future commits faster. Thanks! |
|
cool this works great @StefanIvanciuc, thanks. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
All auth api routes must be accessed via post with json data as post body.
The "/auth/login" route will resolve the provider and return it's name and type. If the provider is an implemented oauth provider, will also return the authorization an url.
Post parameters: email(the email address to authenticate), reauth(if address is already authenticated shall it be reauthenticated?, boolean, optional)
The next step is based on the provider type returned by the route above.
If the provider type is oauth:
If the provider type is generic:
If the provider type is custom: