- Notifications
You must be signed in to change notification settings - Fork397
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
feat(gnofaucet): Github middleware with cooldown#3808
base:master
Are you sure you want to change the base?
feat(gnofaucet): Github middleware with cooldown#3808
Conversation
🛠 PR Checks SummaryAllAutomated Checks passed. ✅ Manual Checks (for Reviewers):
Read More🤖 This bot helps streamline PR reviews by verifying automated checks and providing guidance for contributors and reviewers. ✅ Automated Checks (for Contributors):🟢 Maintainers must be able to edit this pull request (more info) ☑️ Contributor Actions:
☑️ Reviewer Actions:
📚 Resources:Debug
|
Codecov ReportAttention: Patch coverage is 📢 Thoughts on this report?Let us know! |
I didn't follow up on this 🤦♂️ I think the general idea of this PR is good, but the execution needs to be changed a bit. I'm not sure if we should require a GitHub app for verification. Is there a workaround for this? We would add a button on the modal UI for this specific network that says "Connect GitHub" or something similar, and the middleware should check if the user's account matches some criteria (we'll define it, no worries). cc@alexiscolin |
Hello thanks for taking a look :) I think there is not a way ensure user is owner of that account without having a Github Oauth app but I'll take a look. (If problem is the difficulty, whole process takes like 30 seconds). |
zxxma commentedMar 2, 2025
Yes, we have to make sure user the gh owner, username is not sufficient. |
Got it, so there is no way to avoid the GH app. The permissions it requires should be suuuuuuuper minimal @alexiscolin How do you think the flow should look like on the Faucet Hub modal? |
@alexiscolin for reference,https://gnolove.world/ has GitHub & Adena integration |
Hello@zivkovicmilos For github Oauth we have 2 elements client_id and client_secret.
If I understand correctly you want to have only one set of client_id/client secret among all faucets ? the problem I see with this is that we would need to share the secret to all new and old faucets. The flow I was thinking about is for each faucet to create his own github Application so they will have their own secret. The client_id is safe to share (like the recapcha key) so we would be able to share on faucet hub likethis:
About this point: if we do not pass any scope (on the faucet hub), by default we only obtain access to public information the flow can work with this level of permissions. ![]() |
I took a look at the current, proposed, and ideal flows, and here is my suggestion:
For the cooldown: What do you think?
|
We need the GH login for very specific networks. Others will use the captcha like they do now |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
Thank you for the feature :)
I did a pre-review for you even though you're in draft to maximize timing margins.
It would be great to go over all the code again to comment it 🙏
Sorry for the spam, misclicked onApprove
then 3 times onRequest Changes
haha
contribs/gnofaucet/serve.go Outdated
ghClientID string | ||
maxBalance int64 | ||
ghClientSecret string |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
Nitpick
ghClientIDstring | |
maxBalanceint64 | |
ghClientSecretstring | |
ghClientIDstring | |
ghClientSecretstring | |
maxBalanceint64 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
BTW, thisghClientSecret
should be able to be passed via an environment variable rather than a flag for increased security.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
you're right changed here :) thanks for your review
dede43c
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
Thanks 👍 good to have the option to it pass through an environment variable, we could have kept the flags to have both options.
I'll let@zivkovicmilos chose if he prefers to have both or just the environment variable to resolve this conversation.
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
063a6d0
tod4b5c70
Compared4b5c70
to62d710a
CompareCo-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
4c1ea64
todede43c
CompareThere was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
LGTM 👍 just waiting@zivkovicmilos review before merging
related to#3781
Related faucet-hub PR:
gnolang/faucet-hub#41
This pull request introduces two key features to gnofaucet:
getGithubMiddleware: A new middleware that checks for a code query parameter in the URL. It attempts to exchange this code for a GitHub token via OAuth. If the code is valid, the middleware retrieves the GitHub login associated with the token.
Cooldown Period: This feature allows for a configurable cooldown period (1 hour in this case). If the user attempts to claim tokens again before the cooldown period expires, the middleware will reject the request.
Additionally, we could enhance the functionality by implementing checks for account age, pull requests, commits, or verifying if the user belongs to a specific organization.
screen-capture.8.webm