Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

divviup-api could manage collector auth tokens for subscribers #418

Open
tgeoghegan opened this issue Aug 17, 2023 · 1 comment
Open

divviup-api could manage collector auth tokens for subscribers #418

tgeoghegan opened this issue Aug 17, 2023 · 1 comment

Comments

@tgeoghegan
Copy link
Contributor

We generate a unique collector auth token for each task and then expect subscribers to get them from divviup-api and subsequently use them to authenticate requests to the Leader's collection API.

It would be nice if divviup-api had a wrapper around the DAP layer collection API. It could verify that the client is logged in as a user who has appropriate privileges on the task and then make a collection request to the leader on their behalf.

@jbr
Copy link
Contributor

jbr commented Aug 18, 2023

We could also provide an cli for decrypting the collection result if we save the private part of the hpke config for them?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants