feat: new authentication mechanism (access/refresh token)#665
Merged
theborakompanioni merged 11 commits intomasterfrom Oct 8, 2023
Merged
feat: new authentication mechanism (access/refresh token)#665theborakompanioni merged 11 commits intomasterfrom
theborakompanioni merged 11 commits intomasterfrom
Conversation
1625647 to
c8a167e
Compare
Collaborator
Author
|
Just a heads-up: Websocket auth not addressed yet. |
f4811da to
470cb80
Compare
Commit was temporarily till the new auth mechanism can be handled. This reverts commit c31ba67.
Collaborator
Author
Worked out-of-the-box in my tests. 🙌 |
Collaborator
Author
|
Ready for review. |
|
worked smooth on my side in dev env |
editwentyone
approved these changes
Oct 6, 2023
Collaborator
Author
|
We definitely need more reviewers and testers. Someone also needs to audit at the code. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves #663.
This PR adds handling for the new JWT auth mechanism.
From JSON-RPC-API-using-jmwalletd.md#rules-about-making-requests:
The token is refreshed every 22.5 minutes (30min * 0.75). In dev mode more often (every 60 seconds).
There is currently a problem upstream with handling wallets that contain spaces in their filename, should be fixed with JoinMarket-Org/joinmarket-clientserver#1562. Nonetheless, the code can already be reviewed and should not be affected by the changes.
How to test
Rebuild the dev docker environment
npm run regtest:rebuildand verify:Misc
Api.Helper.parseAuthPropsis temporary and can be removed in refactor: Use typed responses for api calls #670.masteragain.