Skip to content

ojo_auth overhaul #185

Description

@brancengregory

Overarching Goal:

  • Create an ojo_auth function that is nice to use interactively to set up an analysts personal, long-lived workspace.
  • Use the same function to authenticate programatically in a deployed setting, especially github actions and google cloud run instances

Currently, ojo_auth:

  • Gets system home env var
  • Looks for system .Renviron file
  • Looks for system ssl certs
    • Expects them to be in a very specific location, $HOME/.postgresql/ojodb/*
    • Errors is they aren't found
  • Toggles on whether to edit the .Renvironment file permanently
    • If yes:
      • Creates a backup if a sys .Renviron exists
        • Toggles on whether to overwrite this file
          • If yes, will remove OJO_ env vars before proceeding
          • If no, error
      • Creates a new sys .Renviron if not
      • Writes .Renviron fields
        • Hardcodes verify-ca as SSL_MODE
    • If no:
      • Uses Sys.setenv to set values temporarily

It wants to, but doesn't succeed in:

  • Allowing for an admin vs default user setup
    • Mostly not working because role switching isn't set up downstream

It maybe shouldn't:

  • Handle admin vs default since this can be toggled at the ojo_connect layer via sql, independent of base auth config
  • Edit the .Renviron directly

It needs to:

  • Gracefully handle windows paths
  • Not hardcode ssl cert location
    • Allow locations or individual file paths to be passed for ssl certs
  • Should be able to ingest from
    • Function Arguments
    • Config/yaml file
    • Renviron
    • System Env Variables

It could:

  • Set file mode (0600) of ssl key
  • Read ojodb specific R options
  • Get ssl certs via bitwarden vault
  • Integrate deeply with googlesecretmanager
  • Use a special list argument that helps build config values
    • This pattern allows easier change of arguments required, etc.
    • Could be used by bitwarden/secretmanager packages or helpers to inject their values directly by producing the correct list
  • Have no breaking changes

Activity

  1. added
    performanceSomething is working, but not optimally
    enhancementNew feature or request
    and removed
    performanceSomething is working, but not optimally
    on Aug 13, 2025
  2. linked a pull request that will close this issueOverhaul ojo_auth #189on Aug 14, 2025
  3. added this to the ojodb 3.0 milestone on Aug 14, 2025
  4. linked a pull request that will close this issueAuth #191on Aug 14, 2025
  5. linked a pull request that will close this issueojodb v3 #192on Aug 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

enhancementNew feature or request

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions