Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Replace Basic Authentication with JWT Tokens, Added Login Page - #2252

Closed
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system
Closed

Replace Basic Authentication with JWT Tokens, Added Login Page#2252
TheElixZammuto wants to merge 6 commits into
masterfrom
feat/new-session-system

Conversation

@TheElixZammuto

Copy link
Copy Markdown
Member

Description

This PR replaces the current Login Page (which is based of the Basic Authentication) with a custom Login Page that implements Cookies + JWT to handle the session system.

This allows us to customize the UX of the login page, and it's more compatible with password managers.

The JWT Key is generated on the fly by Sunshine on each boot and is kept in memory, this allows us to not fiddle with revocation lists and storing safely the encryption key. The only side effect is that the credentials will be invalidated on a Sunshine Reboot, but the Web UI is already capable to handle this edge case and show a login modal when the credentials expire without reloading the entiere page.

This breaks the current API Authentication, but nobody uses the Web UI API as far as we know. If so, let us know!

Screenshot

2024-03-13 21_15_35-Sunshine e altre 4 pagine - Profilo 1 - Microsoft​ Edge
2024-03-13 21_26_13-Sunshine e altre 6 pagine - Profilo 1 - Microsoft​ Edge

Issues Fixed or Closed

https://ideas.moonlight-stream.org/posts/329/sunshine-use-login-page-rather-than-login-prompt

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

Branch Updates

LizardByte requires that branches be up-to-date before merging. This means that after any PR is merged, this branch
must be updated before it can be merged. You must also
Allow edits from maintainers.

  • I want maintainers to keep my branch updated

Comment thread.gitmodules Outdated
Comment threadsrc/confighttp.cpp Outdated
Comment threadthird-party/jwt-cpp
Comment threadsrc/confighttp.cpp
Comment threadsrc_assets/common/assets/web/fetch.js Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
Comment threadsrc_assets/common/assets/web/login.html Outdated
@TheElixZammuto
TheElixZammutoforce-pushed the feat/new-session-system branch from 44fdc58 to 8ba64ffCompareMarch 17, 2024 15:33
@Nonary

This comment was marked as spam.

@TheElixZammuto

Copy link
Copy Markdown
MemberAuthor

Hey, just curious, do we have to replace the basic authentication? I'd rather have it added as an additional authentication method. The goal is to reduce risk, but I don't think its necessary to totally kill off basic auth as its still a secure method, just not really recommended for browser usage due to it exposing password every request.

Simply to simplify the authentication methods and not supporting both of them. This could be useful in situations where we would like to add different/new types of authentication systems without having to deal with this. btw I'll let @ReenigneArcher and @cgutman decide on that, I don't have a very strong opinion on that

@ReenigneArcher

Copy link
Copy Markdown
Member

I agree with Elix. Less code to maintain would be my preference.

@Nonary

This comment was marked as spam.

@ReenigneArcher

Copy link
Copy Markdown
Member

@Nonary are you using the API for anything? I thought you were parsing the logs files for your projects.

We did a search on GitHub and didn't really find anyone doing anything with our API.

@codecov

codecovBot commented Apr 27, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 1.80180% with 109 lines in your changes missing coverage. Please review.

Project coverage is 6.16%. Comparing base (7fb8c76) to head (3888ec8).
Report is 326 commits behind head on master.

Files with missing linesPatch %Lines
src/confighttp.cpp1.80%83 Missing and 26 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #2252 +/- ##
=========================================
- Coverage 6.17% 6.16% -0.02% 
=========================================
Files 86 86 Lines 17546 17644 +98 Branches 8190 8263 +73 =========================================
+ Hits 1083 1087 +4 + Misses 15410 14725 -685 - Partials 1053 1832 +779 
FlagCoverage Δ
Linux4.23% <0.00%> (-0.04%)⬇️
Windows2.03% <0.00%> (-0.02%)⬇️
macOS-128.67% <2.15%> (+0.08%)⬆️
macOS-137.79% <1.07%> (-0.05%)⬇️
macOS-148.12% <1.07%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/confighttp.cpp1.28% <1.80%> (+0.52%)⬆️

... and 25 files with indirect coverage changes

Comment threadsrc/confighttp.cpp

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that we are already refactoring stuff here, can we move out all authentication logic/implementation to another file like http_authenticator or something, and only call it here?

Would also make it easier to unit test, fix, replace or even support multiple auth styles in the future.

@LizardByte-bot

Copy link
Copy Markdown
Member

It looks like this PR has been idle for 90 days. If it's still something you're working on or would like to pursue, please leave a comment or update your branch. Otherwise, we'll be closing this PR in 10 days to reduce our backlog. Thanks!

@LizardByteLizardByte deleted a comment from EpirrSep 16, 2024
@ReenigneArcher

Copy link
Copy Markdown
Member

PR replaced by #2995.

@Nonary

Copy link
Copy Markdown
Contributor

I'm overtaking this with #3999

Submitting comment so that those who were previously following this PR are notified that this feature might be added to sunshine coming soon.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants

@TheElixZammuto@Nonary@ReenigneArcher@LizardByte-bot@cgutman@Hazer