-
Notifications
You must be signed in to change notification settings - Fork 12
Refactor users service #70
Conversation
a4a11a8 to
8939dc9
Compare
| }); | ||
| }); | ||
|
|
||
| app.post('/login', function(req, res){ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So one cool thing that affects development is that we no longer have to connect to the production database on the acm server to login to the website. Now, in development, the users service talks to crowd with the credentials and basically does a find or create User (fetching additional info like their name automatically) and returning it along with the session token.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sounds cool, can you explain more? Is login still hitting crowd directly or is it behind users now?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
from my understanding, Crowd would be behind users, so login would go through user-service
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, login is behind users service now. I think we want the eventual goal to be that only users service talks to crowd. @bcongdon and I discussed this previously and we believe that would be best practice. For example, it would move the logic of the validation-factors body that needs to be there for any crowd request to go to the users service. And it would make the users service actually behave as a service for all things users.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The main requirement is the interface is simple enough that if you only need auth there is a straight forward route. The only concern I have is if we throw out crowd or we throw out the users service that a massive amount of functionality goes out with it since the two are very closely tied now
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Since crowd served only as a session provider and users was a members store, coupling them makes sense in the ad context but is mixing roles in the service context
8939dc9 to
7fc1792
Compare
7fc1792 to
d369386
Compare
See acm-uiuc/groot-users-service#6 for list / updates