|
| 1 | +.. _backend-auth-dummy: |
| 2 | + |
| 3 | +Dummy Auth provider |
| 4 | +=================== |
| 5 | + |
| 6 | +Description |
| 7 | +----------- |
| 8 | + |
| 9 | +This auth provider allows to sign-in with any username and password, and and then issues an access token. |
| 10 | + |
| 11 | +After successful auth, username is saved to backend database. It is then used for creating audit records for any object change, see ``changed_by`` field. |
| 12 | + |
| 13 | +Interaction schema |
| 14 | +------------------ |
| 15 | + |
| 16 | +.. dropdown:: Interaction schema |
| 17 | + |
| 18 | + .. plantuml:: |
| 19 | + |
| 20 | + @startuml |
| 21 | + title DummyAuthProvider |
| 22 | + participant "Client" |
| 23 | + participant "Backend" |
| 24 | + |
| 25 | + == POST v1/auth/token == |
| 26 | + |
| 27 | + activate "Client" |
| 28 | + alt Successful case |
| 29 | + "Client" -> "Backend" ++ : login + password |
| 30 | + "Backend" --> "Backend" : Password is completely ignored |
| 31 | + "Backend" --> "Backend" : Check user in internal backend database |
| 32 | + "Backend" -> "Backend" : Create user if not exist |
| 33 | + "Backend" -[#green]> "Client" -- : Generate and return access_token |
| 34 | + |
| 35 | + else User is blocked |
| 36 | + "Client" -> "Backend" ++ : login + password |
| 37 | + "Backend" --> "Backend" : Password is completely ignored |
| 38 | + "Backend" --> "Backend" : Check user in internal backend database |
| 39 | + "Backend" x-[#red]> "Client" -- : 401 Unauthorized |
| 40 | + |
| 41 | + else User is deleted |
| 42 | + "Client" -> "Backend" ++ : login + password |
| 43 | + "Backend" --> "Backend" : Password is completely ignored |
| 44 | + "Backend" --> "Backend" : Check user in internal backend database |
| 45 | + "Backend" x-[#red]> "Client" -- : 404 Not found |
| 46 | + end |
| 47 | + |
| 48 | + == GET v1/namespaces == |
| 49 | + |
| 50 | + alt Successful case |
| 51 | + "Client" -> "Backend" ++ : access_token |
| 52 | + "Backend" --> "Backend" : Validate token |
| 53 | + "Backend" --> "Backend" : Check user in internal backend database |
| 54 | + "Backend" -> "Backend" : Get data |
| 55 | + "Backend" -[#green]> "Client" -- : Return data |
| 56 | + |
| 57 | + else Token is expired |
| 58 | + "Client" -> "Backend" ++ : access_token |
| 59 | + "Backend" --> "Backend" : Validate token |
| 60 | + "Backend" x-[#red]> "Client" -- : 401 Unauthorized |
| 61 | + |
| 62 | + else User is blocked |
| 63 | + "Client" -> "Backend" ++ : access_token |
| 64 | + "Backend" --> "Backend" : Validate token |
| 65 | + "Backend" --> "Backend" : Check user in internal backend database |
| 66 | + "Backend" x-[#red]> "Client" -- : 401 Unauthorized |
| 67 | + |
| 68 | + else User is deleted |
| 69 | + "Client" -> "Backend" ++ : access_token |
| 70 | + "Backend" --> "Backend" : Validate token |
| 71 | + "Backend" --> "Backend" : Check user in internal backend database |
| 72 | + "Backend" x-[#red]> "Client" -- : 404 Not found |
| 73 | + end |
| 74 | + |
| 75 | + deactivate "Client" |
| 76 | + @enduml |
| 77 | + |
| 78 | +Configuration |
| 79 | +------------- |
| 80 | + |
| 81 | +.. autopydantic_model:: syncmaster.backend.settings.auth.dummy.DummyAuthProviderSettings |
| 82 | +.. autopydantic_model:: syncmaster.backend.settings.auth.jwt.JWTSettings |
0 commit comments