This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
This repository was archived by the owner on Feb 18, 2024. It is now read-only.

Use the GitHub API for all operations - #107

Closed
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16
Closed

Use the GitHub API for all operations#107
tamird wants to merge 2 commits into
jspm:masterfrom
tamird:private-auth-0.16

Conversation

@tamird

Copy link
Copy Markdown
Contributor

As discussed in #99.

If this LGTY I'll open the same PR against 0.17.

@guybedford

@tamird

Copy link
Copy Markdown
ContributorAuthor

cc @adamburgess

Comment threadgithub.js
var self = this, envMap = {
ca: 'GIT_SSL_CAINFO',
cert: 'GIT_SSL_CERT',
key: 'GIT_SSL_KEY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you justify deciding to remove support for this?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're no longer execing, so this make no sense now.

On Sep 6, 2016 12:26, "Guy Bedford" notifications@github.com wrote:

In github.js
#107 (comment):

this.defaultRequestOptions = {
strictSSL: 'strictSSL' in options ? options.strictSSL : true
};

  • if (!this.defaultRequestOptions.strictSSL) {
  • this.execOpt.env.GIT_SSL_NO_VERIFY = '1'

- }

  • var self = this, envMap = {
  • ca: 'GIT_SSL_CAINFO',
  • cert: 'GIT_SSL_CERT',
  • key: 'GIT_SSL_KEY'

Can you justify deciding to remove support for this?


You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
https://github.com/jspm/github/pull/107/files/35ce9c9ae8aeafb727b9467ef19c09f398323dbc#r77669492,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ABdsPLU1rEx9iaRUFTNoaXjwLsMBCTaoks5qnZQlgaJpZM4J2AfN
.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Unfortunately my domain knowledge here isn't up to scratch, and I can't merge this without a comprehensive review, especially after all the issues we had with the last PR.

If anyone is able to review this that would be a great help.

@tamirdtamird mentioned this pull request Sep 6, 2016
@maxlang

Copy link
Copy Markdown

I looked through this code and I've run test.js with both the current repo and a private repo and lookup works fine.

LGTM if this works with Github Enterprise

@adamburgess

Copy link
Copy Markdown

using only the api means that without a token, after 30 installs of a github repo it'll just die, no fallback or anything
no error messages either in this, if github errors out you tell jspm the repo wasn't found
yes, I didn't continue on my PR, but at the very least it had the fallback to git+https

@tamird

Copy link
Copy Markdown
ContributorAuthor

I've added the standard api limit error messages.

In my experience, all non-trivial jspm installs without authentication fail - even after this change, trivial projects will continue to succeed and non-trivial ones will continue to fail.

The complication of the fallback doesn't, in my opinion, justify the complexity, but I'm willing to be convinced.

Reverting the original changes should be a non-starter. Requiring users to provide privileged tokens is a serious security concern.

@guybedford

Copy link
Copy Markdown
Member

Thanks @tamird. Authentication tokens in GitHub can be made to only be read only. The only difference seems to me the inclusion of the user name, but at the cost of hurting unauthenticated workflows.

Without an alternative the best route forward is still looking like reverting that work.

@adamburgess

Copy link
Copy Markdown

@guybedford@tamird just to clarify, what work are you talking about reverting?

@tamird

Copy link
Copy Markdown
ContributorAuthor

@guybedford even "Read only" tokens are overly privileged - they allow reading private repos, which should not be required for public-only jspm invocations.

@adamburgess

Copy link
Copy Markdown

@tamird so are you saying that tokens shouldn't be used and/or opt-in? because just above you said it wasn't worth it?

also from my PR, using git+https is as simple as require('./ls-remote.js') and calling it with the repo to get a promise. (though errors are not handled as best they could be, I seem to remember. Error handling is hell.)

@tamird

Copy link
Copy Markdown
ContributorAuthor

@adamburgess here's the context: #90

before that PR, tokens always had to be privileged.

@adamburgess

adamburgess commented Sep 22, 2016

Copy link
Copy Markdown

@tamird when creating a github token, you can opt to select no scopes at all: https://developer.github.com/v3/oauth/#scopes
-> Grants read-only access to public information (includes public user profile info, public repository info, and gists)

also, to prevent errors like #109, on setup one could check the response X-OAuth-Scopes header for repo and show a notice, e.g.:

This token does not have the repo privilege. If you wanted to use private repositories, please create a new token with that scope. Otherwise, you can safely ignore this warning.

(you could even go farther as to warn if the token given is way too privileged and has too many scopes that jspm will never use)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true, and yet it didn't work. See #89.

@adamburgess

Copy link
Copy Markdown

I don't see anything stating that it doesn't work, there

@tamird

Copy link
Copy Markdown
ContributorAuthor

That issue is about unprivileged tokens not working with JSPM (they had to have public_repo, at a minimum). So your suggestion about not selecting any scopes is correct, but the old implementation (pre #90) did not work with such tokens.

@adamburgess

Copy link
Copy Markdown

but that's what this PR is for: a new implementation ;)

@tamird

Copy link
Copy Markdown
ContributorAuthor

Yes, that's true. Perhaps you could open an alternative PR to flesh out
your suggestion.

On Sep 22, 2016 08:46, "Adam Burgess" notifications@github.com wrote:

but that's what this PR is for: a new implementation ;)


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#107 (comment), or mute
the thread
https://github.com/notifications/unsubscribe-auth/ABdsPCRX6ZwoGBn7sspHiBl5ZqNfWO_tks5qsniVgaJpZM4J2AfN
.

@tamirdtamird closed this Apr 29, 2017
@tamird
tamird deleted the private-auth-0.16 branch April 29, 2017 03:25
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tamird@guybedford@maxlang@adamburgess