-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add authentication with multiple jwt providers #694
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
BREAKING CHANGE: AUTH_CONFIG is now a required environment variable. If it is not configured whispr will not start.
Babbafett
previously approved these changes
Feb 16, 2022
nikola-kovacevic
previously approved these changes
Feb 16, 2022
over-flo79
dismissed stale reviews from nikola-kovacevic and Babbafett
via
February 23, 2022 16:44
ca48ddd
over-flo79
previously approved these changes
Feb 23, 2022
over-flo79
force-pushed
the
feat/multi-auth
branch
from
February 23, 2022 17:08
ca48ddd
to
56eeb98
Compare
alastasWow
approved these changes
Feb 24, 2022
🎉 This PR is included in version 4.0.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Please check if the PR fulfills these requirements
What kind of change does this PR introduce?
Adds JWT authentication to Whispr, accepting configuration of multiple providers so JWTs can be accepted from multiple applications. Initial implementation for #696.
What is the current behavior?
No authentication.
What is the new behavior?
whispsAuthBeta
to begin testing the implementation in a deployed environment (no breaking change for the existing API)What was the testing strategy?
Unit tests
E2E tests
Load tests
Ran a simple test with the following scenario:
whisps
query with a limit of 100 records once every iterationwhisps
query withwhispsAuthBeta
Results
Small impact to performance. Average response time increased by approximately 1.6ms for the auth enabled query. The test results can be variable between runs as we are dependent on the Gitpod infrastructure, but I repeated a few times and saw an increase of just over 1ms in most cases.
This means that enabling authentication in production should not have any noticeable impact on system performance; the change is definitely justified considering the security benefits it brings.
See below for detailed test results.
Output with no auth
Output with auth
How has the change been documented?
Does this PR introduce a breaking change?
Yes 😈
Other information
This PR does not cover authorization - that needs to be addressed in the future to further secure the API at the record level (for example access per application ID).