Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

feat(gnofaucet): Github middleware with cooldown#3808

Open
Villaquiranm wants to merge20 commits intognolang:master
base:master
Choose a base branch
Loading
fromVillaquiranm:feat/gh-middleware-with-cooldown

Conversation

Villaquiranm
Copy link
Contributor

@VillaquiranmVillaquiranm commentedFeb 22, 2025
edited
Loading

related to#3781
Related faucet-hub PR:
gnolang/faucet-hub#41

This pull request introduces two key features to gnofaucet:

getGithubMiddleware: A new middleware that checks for a code query parameter in the URL. It attempts to exchange this code for a GitHub token via OAuth. If the code is valid, the middleware retrieves the GitHub login associated with the token.

Cooldown Period: This feature allows for a configurable cooldown period (1 hour in this case). If the user attempts to claim tokens again before the cooldown period expires, the middleware will reject the request.

Additionally, we could enhance the functionality by implementing checks for account age, pull requests, commits, or verifying if the user belongs to a specific organization.

screen-capture.8.webm

zxxma reacted with thumbs up emojialexiscolin reacted with eyes emoji
@Gno2D2
Copy link
Collaborator

Gno2D2 commentedFeb 22, 2025
edited
Loading

🛠 PR Checks Summary

AllAutomated Checks passed. ✅

Manual Checks (for Reviewers):
  • IGNORE the bot requirements for this PR (force green CI check)
Read More

🤖 This bot helps streamline PR reviews by verifying automated checks and providing guidance for contributors and reviewers.

✅ Automated Checks (for Contributors):

🟢 Maintainers must be able to edit this pull request (more info)
🟢 Pending initial approval by a review team member, or review from tech-staff

☑️ Contributor Actions:
  1. Fix any issues flagged by automated checks.
  2. Follow the Contributor Checklist to ensure your PR is ready for review.
    • Add new tests, or document why they are unnecessary.
    • Provide clear examples/screenshots, if necessary.
    • Update documentation, if required.
    • Ensure no breaking changes, or includeBREAKING CHANGE notes.
    • Link related issues/PRs, where applicable.
☑️ Reviewer Actions:
  1. Complete manual checks for the PR, including the guidelines and additional checks if applicable.
📚 Resources:
Debug
Automated Checks
Maintainers must be able to edit this pull request (more info)

If

🟢 Condition met└── 🟢 And    ├── 🟢 The base branch matches this pattern: ^master$    └── 🟢 The pull request was created from a fork (head branch repo: Villaquiranm/gno)

Then

🟢 Requirement satisfied└── 🟢 Maintainer can modify this pull request
Pending initial approval by a review team member, or review from tech-staff

If

🟢 Condition met└── 🟢 And    ├── 🟢 The base branch matches this pattern: ^master$    └── 🟢 Not (🔴 Pull request author is a member of the team: tech-staff)

Then

🟢 Requirement satisfied└── 🟢 If    ├── 🟢 Condition    │   └── 🟢 Or    │       ├── 🟢 At least 1 user(s) of the organization reviewed the pull request (with state "APPROVED")    │       ├── 🟢 At least 1 user(s) of the team tech-staff reviewed pull request    │       └── 🔴 This pull request is a draft    └── 🟢 Then        └── 🟢 Not (🔴 This label is applied to pull request: review/triage-pending)
Manual Checks
**IGNORE** the bot requirements for this PR (force green CI check)

If

🟢 Condition met└── 🟢 On every pull request

Can be checked by

  • Any user with comment edit permission

@codecovCodecov
Copy link

codecovbot commentedFeb 22, 2025
edited
Loading

Codecov Report

Attention: Patch coverage is46.74556% with90 lines in your changes missing coverage. Please review.

Files with missing linesPatch %Lines
contribs/gnofaucet/serve.go0.00%35 Missing⚠️
contribs/gnofaucet/gh.go47.36%29 Missing and 1 partial⚠️
contribs/gnofaucet/coins.go53.84%16 Missing and 2 partials⚠️
contribs/gnofaucet/cooldown.go81.57%5 Missing and 2 partials⚠️

📢 Thoughts on this report?Let us know!

@VillaquiranmVillaquiranm changed the titlefeat: faucet github middleware with coolDownfeat(gnofaucet): Github middleware with cooldownFeb 22, 2025
@zivkovicmiloszivkovicmilos self-requested a reviewFebruary 22, 2025 17:01
@KoutekiKouteki added the 🌱 featureNew update to Gno labelFeb 22, 2025
@zivkovicmilos
Copy link
Member

I didn't follow up on this 🤦‍♂️

I think the general idea of this PR is good, but the execution needs to be changed a bit.

I'm not sure if we should require a GitHub app for verification. Is there a workaround for this?
We essentially just need the GH username, no other access.

We would add a button on the modal UI for this specific network that says "Connect GitHub" or something similar, and the middleware should check if the user's account matches some criteria (we'll define it, no worries). cc@alexiscolin

Villaquiranm reacted with rocket emoji

@Villaquiranm
Copy link
ContributorAuthor

I didn't follow up on this 🤦‍♂️

I think the general idea of this PR is good, but the execution needs to be changed a bit.

I'm not sure if we should require a GitHub app for verification. Is there a workaround for this? We essentially just need the GH username, no other access.

We would add a button on the modal UI for this specific network that says "Connect GitHub" or something similar, and the middleware should check if the user's account matches some criteria (we'll define it, no worries). cc@alexiscolin

Hello thanks for taking a look :)

I think there is not a way ensure user is owner of that account without having a Github Oauth app but I'll take a look. (If problem is the difficulty, whole process takes like 30 seconds).
or maybe the idea was to just have a username input without ensuring user is owner ?

@zxxma
Copy link

or maybe the idea was to just have a username input without ensuring user is owner ?

Yes, we have to make sure user the gh owner, username is not sufficient.
Otherwise, faucet farming will be too simple.

zivkovicmilos reacted with thumbs up emoji

@zivkovicmilos
Copy link
Member

or maybe the idea was to just have a username input without ensuring user is owner ?

Yes, we have to make sure user the gh owner, username is not sufficient. Otherwise, faucet farming will be too simple.

@zxxma@Villaquiranm

Got it, so there is no way to avoid the GH app.
Can we make it open sourced on the gnoverse org?

The permissions it requires should be suuuuuuuper minimal

@alexiscolin How do you think the flow should look like on the Faucet Hub modal?
I assume there is gonna be a button "Verify with GitHub", if the user has not authenticated before, and when they do, some kind of text confirmation in the modal?

alexiscolin reacted with eyes emoji

@KoutekiKouteki removed the request for review froma teamMarch 10, 2025 10:05
@Kouteki
Copy link
Contributor

@alexiscolin for reference,https://gnolove.world/ has GitHub & Adena integration

alexiscolin reacted with heart emoji

@KoutekiKouteki requested a review fromaeddiMarch 10, 2025 12:55
@Villaquiranm
Copy link
ContributorAuthor

Hello@zivkovicmilos
Sorry for the delay,

For github Oauth we have 2 elements client_id and client_secret.

Can we make it open sourced on the gnoverse org

If I understand correctly you want to have only one set of client_id/client secret among all faucets ? the problem I see with this is that we would need to share the secret to all new and old faucets.

The flow I was thinking about is for each faucet to create his own github Application so they will have their own secret. The client_id is safe to share (like the recapcha key) so we would be able to share on faucet hub likethis:

The permissions it requires should be suuuuuuuper minimal

About this point: if we do not pass any scope (on the faucet hub), by default we only obtain access to public information the flow can work with this level of permissions.

image

@alexiscolin
Copy link
Member

I took a look at the current, proposed, and ideal flows, and here is my suggestion:

  1. On the faucet UI, you request the drip. (The link should be marked as external, so users understand they will be redirected to GitHub.)
  2. You are redirected to GitHub to accept the request.
  3. You are then automatically redirected back to the faucet UI, returning to the pending state. (A refactor is needed here, as I don't think this is currently possible.)
  4. After returning and receiving the transfer notification, the pending state should be updated with either a success or error message, displayed in the modal as it is today.

For the cooldown:
2. Current flow: pending → error message (a new error message should be added for cooldown cases).

What do you think?

Quick question: What happens to users who don’t have a GitHub account? Should we consider using two different drip buttons based on whether the user is logged into GitHub (in this case the GH one would disappear)? I ask since I know a lot of people don't have GH account and will need the faucet to work.

cc@zivkovicmilos@zxxma@Villaquiranm

@zivkovicmilos
Copy link
Member

I took a look at the current, proposed, and ideal flows, and here is my suggestion:

  1. On the faucet UI, you request the drip. (The link should be marked as external, so users understand they will be redirected to GitHub.)
  2. You are redirected to GitHub to accept the request.
  3. You are then automatically redirected back to the faucet UI, returning to the pending state. (A refactor is needed here, as I don't think this is currently possible.)
  4. After returning and receiving the transfer notification, the pending state should be updated with either a success or error message, displayed in the modal as it is today.

For the cooldown: 2. Current flow: pending → error message (a new error message should be added for cooldown cases).

What do you think?

Quick question: What happens to users who don’t have a GitHub account? Should we consider using two different drip buttons based on whether the user is logged into GitHub (in this case the GH one would disappear)? I ask since I know a lot of people don't have GH account and will need the faucet to work.

cc@zivkovicmilos@zxxma@Villaquiranm

@alexiscolin

We need the GH login for very specific networks. Others will use the captcha like they do now

alexiscolin reacted with thumbs up emoji

Copy link
Contributor

@aeddiaeddi left a comment
edited
Loading

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Thank you for the feature :)

I did a pre-review for you even though you're in draft to maximize timing margins.
It would be great to go over all the code again to comment it 🙏

Sorry for the spam, misclicked onApprove then 3 times onRequest Changes haha

Villaquiranm reacted with thumbs up emojiVillaquiranm reacted with eyes emoji
Comment on lines 61 to 63
ghClientID string
maxBalance int64
ghClientSecret string
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Nitpick

Suggested change
ghClientIDstring
maxBalanceint64
ghClientSecretstring
ghClientIDstring
ghClientSecretstring
maxBalanceint64

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

BTW, thisghClientSecret should be able to be passed via an environment variable rather than a flag for increased security.

Copy link
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

you're right changed here :) thanks for your review
dede43c

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Thanks 👍 good to have the option to it pass through an environment variable, we could have kept the flags to have both options.

I'll let@zivkovicmilos chose if he prefers to have both or just the environment variable to resolve this conversation.

aeddi

This comment was marked as duplicate.

aeddi

This comment was marked as duplicate.

aeddi

This comment was marked as duplicate.

aeddi

This comment was marked as duplicate.

Villaquiranmand others added5 commitsMarch 17, 2025 20:58
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
@VillaquiranmVillaquiranmforce-pushed thefeat/gh-middleware-with-cooldown branch from063a6d0 tod4b5c70CompareMarch 19, 2025 18:55
@VillaquiranmVillaquiranmforce-pushed thefeat/gh-middleware-with-cooldown branch fromd4b5c70 to62d710aCompareMarch 19, 2025 19:00
Villaquiranmand others added4 commitsMarch 20, 2025 21:06
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
Co-authored-by: Antoine Eddi <5222525+aeddi@users.noreply.github.com>
@VillaquiranmVillaquiranmforce-pushed thefeat/gh-middleware-with-cooldown branch from4c1ea64 todede43cCompareMarch 20, 2025 20:25
Copy link
Contributor

@aeddiaeddi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

LGTM 👍 just waiting@zivkovicmilos review before merging

Villaquiranm reacted with heart emoji
@aeddiaeddi marked this pull request as ready for reviewMarch 21, 2025 08:41
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers

@aeddiaeddiaeddi approved these changes

@zivkovicmiloszivkovicmilosAwaiting requested review from zivkovicmilos

Assignees

@VillaquiranmVillaquiranm

Labels
🌱 featureNew update to Gno
Projects
Status: In Review
Development

Successfully merging this pull request may close these issues.

7 participants
@Villaquiranm@Gno2D2@zivkovicmilos@zxxma@Kouteki@alexiscolin@aeddi

[8]ページ先頭

©2009-2025 Movatter.jp