-
Notifications
You must be signed in to change notification settings - Fork 58
Allow using a separate key file when setting up 'Sign in with Apple' #4393
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks! I don't know why the documentation was so far off the actual configuration 😅
No worries. I believe I have implemented your change requests now and I appreciate the quick review. Let me know if you don't agree with some changes I did edit: I have built the new resulting MAS cli using this branch and have deployed it fine in my cluster, and verified Apple SSO works. |
…ate_key in db using the provided file (if given)
Feat/populate priv key sync
@sandhose I have now implemented the private key reading in the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for doing this!
} else if let Some(mut siwa) = provider.sign_in_with_apple.clone() { | ||
// if private key file is defined and not private key (raw), we populate the | ||
// private key to hold the content of the private key file. | ||
// private key (raw) takes precedence so both can be defined | ||
// without issues | ||
if siwa.private_key.is_none() { | ||
if let Some(private_key_file) = siwa.private_key_file.take() { | ||
let key = tokio::fs::read_to_string(private_key_file).await?; | ||
siwa.private_key = Some(key); | ||
} | ||
} | ||
let encoded = serde_json::to_vec(&siwa)?; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This does mean that it's possible to end up in the database with no private key if none are set. But I'm fine with that, SiWA is sufficiently niche anyway :)
This change requires using a private key file for Apple Sign-In authentication instead of directly pasting the key content.
Fixes #4391