mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add github device flow for authentication (#8232)
* feat: add github device flow for authentication This will allow us to add a GitHub OAuth provider out-of-the-box to reduce setup requirements. * Improve askpass view * Add routes to improve clarity of git auth * Redesign the git auth page * Refactor to add a page view * Fix sideways layout * Remove legacy notify * Fix git auth redirects * Add E2E tests * Fix route documentation * Fix imports * Remove unused imports * Fix E2E web test * Fix friendly message appearance * Fix layout shifting for full-screen sign-in * Fix height going to 100% * Fix comments
This commit is contained in:
+14
-10
@@ -298,16 +298,20 @@ type TraceConfig struct {
|
||||
}
|
||||
|
||||
type GitAuthConfig struct {
|
||||
ID string `json:"id"`
|
||||
Type string `json:"type"`
|
||||
ClientID string `json:"client_id"`
|
||||
ClientSecret string `json:"-" yaml:"client_secret"`
|
||||
AuthURL string `json:"auth_url"`
|
||||
TokenURL string `json:"token_url"`
|
||||
ValidateURL string `json:"validate_url"`
|
||||
Regex string `json:"regex"`
|
||||
NoRefresh bool `json:"no_refresh"`
|
||||
Scopes []string `json:"scopes"`
|
||||
ID string `json:"id"`
|
||||
Type string `json:"type"`
|
||||
ClientID string `json:"client_id"`
|
||||
ClientSecret string `json:"-" yaml:"client_secret"`
|
||||
AuthURL string `json:"auth_url"`
|
||||
TokenURL string `json:"token_url"`
|
||||
ValidateURL string `json:"validate_url"`
|
||||
AppInstallURL string `json:"app_install_url"`
|
||||
AppInstallationsURL string `json:"app_installations_url"`
|
||||
Regex string `json:"regex"`
|
||||
NoRefresh bool `json:"no_refresh"`
|
||||
Scopes []string `json:"scopes"`
|
||||
DeviceFlow bool `json:"device_flow"`
|
||||
DeviceCodeURL string `json:"device_code_url"`
|
||||
}
|
||||
|
||||
type ProvisionerConfig struct {
|
||||
|
||||
@@ -0,0 +1,90 @@
|
||||
package codersdk
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/http"
|
||||
)
|
||||
|
||||
type GitAuth struct {
|
||||
Authenticated bool `json:"authenticated"`
|
||||
Device bool `json:"device"`
|
||||
Type string `json:"type"`
|
||||
|
||||
// User is the user that authenticated with the provider.
|
||||
User *GitAuthUser `json:"user"`
|
||||
// AppInstallable is true if the request for app installs was successful.
|
||||
AppInstallable bool `json:"app_installable"`
|
||||
// AppInstallations are the installations that the user has access to.
|
||||
AppInstallations []GitAuthAppInstallation `json:"installations"`
|
||||
// AppInstallURL is the URL to install the app.
|
||||
AppInstallURL string `json:"app_install_url"`
|
||||
}
|
||||
|
||||
type GitAuthAppInstallation struct {
|
||||
ID int `json:"id"`
|
||||
Account GitAuthUser `json:"account"`
|
||||
ConfigureURL string `json:"configure_url"`
|
||||
}
|
||||
|
||||
type GitAuthUser struct {
|
||||
Login string `json:"login"`
|
||||
AvatarURL string `json:"avatar_url"`
|
||||
ProfileURL string `json:"profile_url"`
|
||||
Name string `json:"name"`
|
||||
}
|
||||
|
||||
// GitAuthDevice is the response from the device authorization endpoint.
|
||||
// See: https://tools.ietf.org/html/rfc8628#section-3.2
|
||||
type GitAuthDevice struct {
|
||||
DeviceCode string `json:"device_code"`
|
||||
UserCode string `json:"user_code"`
|
||||
VerificationURI string `json:"verification_uri"`
|
||||
ExpiresIn int `json:"expires_in"`
|
||||
Interval int `json:"interval"`
|
||||
}
|
||||
|
||||
type GitAuthDeviceExchange struct {
|
||||
DeviceCode string `json:"device_code"`
|
||||
}
|
||||
|
||||
func (c *Client) GitAuthDeviceByID(ctx context.Context, provider string) (GitAuthDevice, error) {
|
||||
res, err := c.Request(ctx, http.MethodGet, fmt.Sprintf("/api/v2/gitauth/%s/device", provider), nil)
|
||||
if err != nil {
|
||||
return GitAuthDevice{}, err
|
||||
}
|
||||
defer res.Body.Close()
|
||||
if res.StatusCode != http.StatusOK {
|
||||
return GitAuthDevice{}, ReadBodyAsError(res)
|
||||
}
|
||||
var gitauth GitAuthDevice
|
||||
return gitauth, json.NewDecoder(res.Body).Decode(&gitauth)
|
||||
}
|
||||
|
||||
// ExchangeGitAuth exchanges a device code for a git auth token.
|
||||
func (c *Client) GitAuthDeviceExchange(ctx context.Context, provider string, req GitAuthDeviceExchange) error {
|
||||
res, err := c.Request(ctx, http.MethodPost, fmt.Sprintf("/api/v2/gitauth/%s/device", provider), req)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer res.Body.Close()
|
||||
if res.StatusCode != http.StatusNoContent {
|
||||
return ReadBodyAsError(res)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// GitAuthByID returns the git auth for the given provider by ID.
|
||||
func (c *Client) GitAuthByID(ctx context.Context, provider string) (GitAuth, error) {
|
||||
res, err := c.Request(ctx, http.MethodGet, fmt.Sprintf("/api/v2/gitauth/%s", provider), nil)
|
||||
if err != nil {
|
||||
return GitAuth{}, err
|
||||
}
|
||||
defer res.Body.Close()
|
||||
if res.StatusCode != http.StatusOK {
|
||||
return GitAuth{}, ReadBodyAsError(res)
|
||||
}
|
||||
var gitauth GitAuth
|
||||
return gitauth, json.NewDecoder(res.Body).Decode(&gitauth)
|
||||
}
|
||||
Reference in New Issue
Block a user