Skip to content
This repository was archived by the owner on Nov 19, 2018. It is now read-only.
Ray Nicholus edited this page Mar 23, 2014 · 14 revisions

Why?

This project is, among other things, an excuse to use Ember.js AngularJS in a non-work context. I'd also really like to create a nicer, more complete UI for Github issues.

Architecture

The goal was to make this a 100% client-side app. However, I can only realistically make this 99% client-side, due to Github's OAuth flow. In order to make privileged requests against Github's API, I am going to use their OAuth2 web application flow. Ultimately, I need to include a bearer token with all privileged requests to Github's API. This is a 3-step process:

  1. Redirect the user to a Github login/access page where they will need to allow nimble to make Github API requests on their behalf.
  2. Handle the redirect from Github's authorize page (in step 1). Here, I will need to verify that this is tied to the request I sent in step 1.
  3. If everything looks good, I'll need to send a POST request back to Github, asking for the token. This step in particular MUST happen server side. Why? First, the POST request must include a secret key assigned to nimble. In most cases, secrets shouldn't be made available to the browser since they can be easily viewed. Second, Github's API doesn't allow accept cross-origin JavaScript based requests for this particular POST request, ostensibly since you should NOT make this request directly from the browser. JSONP is also not possible, since this is a POST.

Libraries

Client

  • Ember.js AngularJS will drive the front-end. See issue #7 for details on why I am switching to Angular.
  • jQuery is also an Ember dependency.
  • Bootstrap is a responsive UI framework.

Server

  • node.js, but I expect (my) server footprint to be extremely limited.

For development, I'm using Web Storm, for now.

Clone this wiki locally