Commit Graph
59 Commits
Author SHA1 Message Date
Bjoern Gruening 4eaba38f2e =?UTF-8?q?In=20FF=20the=20<object>=20attriute=20needs=20to=20be?= =?UTF-8?q?=20from=20type=20'data'=20and=20not=20'src'.=0AChrome=20seems?= =?UTF-8?q?=20to=20be=20happy=20with=20'src'.=20This=20commit=20changes=20?= =?UTF-8?q?it=20back=20to=20'data'.?= 2014-10-18 18:38:04 -04:00
Eric Rasche 0e8289d47f Better failover in all situations
Previously in a specific situation (apache_urls = False and password_auth = True), we saw that users
would see a blank screen rather than an informative error message. This should not happen under any
circumstances.

This has been replaced with logic to handle the failure modes in as sane of a way as possible. If
the above situation is true, we provide the users with their random password and a login box. If any
other bad situation occurs, we pass the error message along to them.

Additionally a new variable "password_auth" has been introduced, describing whether or not passwords
should be used to authenticate users (mostly auto-magically) against their notebooks.

Because we have control over this docker image, it is possible we can handle that specific case
above by convincing ipython to set a content-origin header allowing the galaxy host to make the JS
login request.
2014-10-18 18:38:04 -04:00
Eric Rasche 9142fae801 Updated README with security information 2014-10-18 18:38:04 -04:00
Eric Rasche 62444db82a Accidentally overwrote remote with local changes, reverting 2014-10-18 18:38:04 -04:00
Eric Rasche ef1c20f8d0 Replaced iframe with embed for aesthetics
Now whenever a notebook is loaded we first do a POST to the notebook login URL with the correct
authentication details. This logs us in and stores a cookie for us. Once this is done, (and we know
we were successful) we add the embed/object elements to the body of the page, which the browser then
loads.
2014-10-18 18:38:04 -04:00
Eric Rasche 3a212cd6c2 Completely working login system 2014-10-18 18:38:04 -04:00
Eric Rasche 760bf70359 Added password protection of the notebook 2014-10-18 18:38:04 -04:00
Bjoern Gruening e32f7d1d0f Added the video to the readme file. 2014-10-18 18:38:04 -04:00
Bjoern Gruening 4e1e6cff78 Update README.md
"Next Generation Training" course might be a little bit to much ... ;)
2014-10-18 18:38:04 -04:00
Bjoern Gruening 0ec0413b3b Adopting the help text in the inital welcome Notebook. 2014-10-18 18:38:04 -04:00
Bjoern Gruening f297afd462 Update README.md 2014-10-18 18:38:04 -04:00
Bjoern Gruening e98dd7959f Update README.md 2014-10-18 18:38:04 -04:00
Bjoern Gruening e501e97ddf add image to show the integration of IPython in Galaxy 2014-10-18 18:38:03 -04:00
Bjoern Gruening b0b8b35de4 add some images for better documentation 2014-10-18 18:38:03 -04:00
Bjoern Gruening 97a1a53cf7 Update README.md 2014-10-18 18:38:03 -04:00
Eric Rasche 4f3052fd2b Extracted template into a template file
It was really awful to have that file maintained with the rest of the source code, now it is
separate.
2014-10-18 18:38:03 -04:00
Eric Rasche 27bbce5610 Extracted configuration file
Currently only a few variables, more can be placed here later.
2014-10-18 18:38:03 -04:00
Eric Rasche d96d2fe16e Mentioned nginx 2014-10-18 18:38:03 -04:00
Eric Rasche 9f53d2e94f Updated requirement list 2014-10-18 18:38:03 -04:00
Eric Rasche 5fbf9b884a Added information on template changes required 2014-10-18 18:38:03 -04:00
Eric Rasche c68b15aa04 Todo item completed 2014-10-18 18:38:03 -04:00
Eric Rasche 75d426df52 Added installation information 2014-10-18 18:38:03 -04:00
Eric Rasche 233db5340f Updated text on on template to refer to button colour 2014-10-18 18:38:03 -04:00
Bjoern Gruening 34f7b7d226 remove trailing slash, better save than sorry 2014-10-18 18:38:03 -04:00
Bjoern Gruening bca45b582e change the port detection to parse the universe_wsgi.ini file 2014-10-18 18:38:03 -04:00
Eric Rasche 9b36dfa3bf Passed port and set URL path for ipython
To allow for server administrators to easily secure IPyNBs, we have to stop serving over ports, and
start serving under a sub-path. This change will require the introduction of apache configuration as
a hard requirement for rewriting URLs properly to the backend.

For a given Port $P, IPyNBs are started, listening on 127.0.0.1:$P/ipython/$P/. These are accessed
through that url within galaxy. For the apache style configuration, we remove the first $P and
simply access notebooks at "127.0.0.1/ipython/$P/" which allows the administrator to apply SSL to
the /ipython/ path, thereby securing the notebooks.
2014-10-18 18:38:03 -04:00
Eric Rasche eeffd1bfe4 Attempted better description 2014-10-18 18:38:03 -04:00
Eric Rasche 9f5809dcf1 =?UTF-8?q?Removed=20save=20function=20and=20added=20docs=20since?= =?UTF-8?q?=20Bj=C3=B6rn=20implemented=20save=20button?= 2014-10-18 18:38:03 -04:00
Eric Rasche a24cfdefca Switch over to requiring IPyNB datatype 2014-10-18 18:38:03 -04:00
Eric Rasche 442f501696 lsof translates port names by default
This commit ensures we always receive numerical ports from lsof, rather than service names as
translated by /etc/services
2014-10-18 18:38:03 -04:00
Bjoern Gruening 217fd81c3c more pythonification 2014-10-18 18:38:03 -04:00
Bjoern Gruening 3a4260a0d5 Try again to fix the netstat filtering and cellect all used ports. 2014-10-18 18:38:03 -04:00
Eric Rasche a2330fa7ce Template updates
A couple things of interest are done with the template:

- HTML header
- Markdown cell with instructions as to read/write data from galaxy
- A HIDDEN javascript function to save to galaxy
- Empty cell for next user command.

The hidden javascript function is done by writing the function as part of the notebook and removing
the input text. This is probably very, very fragile and will not survive a closing+reopening but
it's very pleasant looking to just have a button that saves the notebook to galaxy. It's very
visually unobtrusive and that may be more important for new users than having the full code there.

To be able to interact with that button it is required that ipython trust the notebook. This is done
in an update to the docker startup script.
2014-10-18 18:38:03 -04:00
Bjoern Gruening f6c9bebd84 some readme updates 2014-10-18 18:38:03 -04:00
Eric Rasche bab456fd01 Redirect lsof's stderr to ignored device 2014-10-18 18:38:03 -04:00
Eric Rasche d9a29812cc Found port properly 2014-10-18 18:38:03 -04:00
Eric Rasche 01c0633fd8 Added code to obtain port information from galaxy 2014-10-18 18:38:03 -04:00
Eric Rasche e8c619d01b Changed flow style for easier grepping
See the [PyYAML](http://pyyaml.org/wiki/PyYAMLDocumentation) docs for more information as to flow
style. Essentially it should make sure the `conf.yaml` file is greppable, which may be necessary for
IP address whitelisting.
2014-10-18 18:38:03 -04:00
Eric Rasche 4b64a70906 Added remote_host variable to docker conf
In order to whitelist IPs allowed to connect to notebooks, we need to know who the remote target
connecting is. We can blacklist on IP address only, as we have no way of authenticating them. While
we do have access to other information like cookies, we have no SSL nor way to know what
authentication method the galaxy server will be using.
2014-10-18 18:38:03 -04:00
Eric Rasche 7ae8deb202 Rewrote netstat commands as Popen piped commands
The original version actually failed for me. I am led to believe that all the pipes were being
passed to netstat as it said "I don't understand the option ':'" which came from the cut command.
At the cost of simplicity, this should do what we want properly. Alternatively we could move the
awk/cut/sort into python.
2014-10-18 18:38:03 -04:00
Eric Rasche 93ed4fe859 Working load from existing notebooks in history 2014-10-18 18:38:03 -04:00
Bjoern Gruening 7c02e8ce53 Style fixes 2014-10-18 18:38:03 -04:00
Bjoern Gruening 7ebbb74fc7 Remove copying of datatsets from Galaxy to docker. From now on, docker can fetch data from galaxy on demand. 2014-10-18 18:38:03 -04:00
Bjoern Gruening adfee3ba65 add random port assignment for different docker containers, for multiple users 2014-10-18 18:38:03 -04:00
Bjoern Gruening 73d728d1e2 update readme file 2014-10-18 18:38:03 -04:00
Bjoern Gruening 7048f38915 restructure repository layout 2014-10-18 18:38:02 -04:00
Eric Rasche c6559b4d70 Exchanged localhost for proper hostname
`request` provides a `host_url` like "fqdn:port" from which we can extract the FQDN that this server
was accessed at. This is important so that we are accessing the IPyNB on the correct host.
2014-10-18 18:38:02 -04:00
Eric Rasche 93c3695b10 Located full application URL
This should now work properly for galaxy instances hosted on different ports, on different
proxy-prefixes, on different fqdns, etc.
2014-10-18 18:38:01 -04:00
Eric Rasche 6f7e7805a1 Found the API key 2014-10-18 18:38:01 -04:00
Eric Rasche 6950aa2906 Typo, wrong destination and all datasets overwrote one another. This fixes that issue 2014-10-18 18:38:01 -04:00