NIFI-8931 Remove OTP Authentication#5235
Closed
exceptionfactory wants to merge 1 commit intoapache:mainfrom
Closed
NIFI-8931 Remove OTP Authentication#5235exceptionfactory wants to merge 1 commit intoapache:mainfrom
exceptionfactory wants to merge 1 commit intoapache:mainfrom
Conversation
- Removed download-token and ui-extension-token REST resources - Removed getAccessToken functions from JavaScript components
gresockj
approved these changes
Jul 21, 2021
Contributor
gresockj
left a comment
There was a problem hiding this comment.
Verified that this still works with and without OIDC login. Tested downloading from the provenance screen and using a custom UI like JoltTransformJSON. Nice work cleaning up this portion of the code, @exceptionfactory!
Contributor
|
Tested this out with X509 and LDAP, was able to download flow file content, and view in the content browser. I was also able to download template files. Big chunk of code gone, awesome. |
Contributor
Author
|
Thanks for the review @thenatog! |
krisztina-zsihovszki
pushed a commit
to krisztina-zsihovszki/nifi
that referenced
this pull request
Jun 28, 2022
- Removed download-token and ui-extension-token REST resources - Removed getAccessToken functions from JavaScript components Signed-off-by: Nathan Gough <thenatog@gmail.com> This closes apache#5235.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of PR
NIFI-8931 Removes One-time Password authentication and associated token REST resources.
Transitioning to HTTP session cookies for passing JSON Web Tokens in #4988 eliminated the need for OTP authentication when downloading files or launching user interface extensions. Web browsers include HTTP session cookies on requests, which removes the requirement for JavaScript calls to request an access token prior to making requests.
Changes include removal of the OTP authentication services as well as the
download-tokenandui-extension-tokenREST Access Resources, along with the associated JavaScript code.In order to streamline the review of the contribution we ask you
to ensure the following steps have been taken:
For all changes:
Is there a JIRA ticket associated with this PR? Is it referenced
in the commit message?
Does your PR title start with NIFI-XXXX where XXXX is the JIRA number you are trying to resolve? Pay particular attention to the hyphen "-" character.
Has your PR been rebased against the latest commit within the target branch (typically
main)?Is your initial contribution a single, squashed commit? Additional commits in response to PR reviewer feedback should be made on this branch and pushed to allow change tracking. Do not
squashor use--forcewhen pushing to allow for clean monitoring of changes.For code changes:
mvn -Pcontrib-check clean installat the rootnififolder?LICENSEfile, including the mainLICENSEfile undernifi-assembly?NOTICEfile, including the mainNOTICEfile found undernifi-assembly?.displayNamein addition to .name (programmatic access) for each of the new properties?For documentation related changes:
Note:
Please ensure that once the PR is submitted, you check GitHub Actions CI for build issues and submit an update to your PR as soon as possible.