3 ms·
A former student of mine (Vera Yaseneva) redesigned our old auth architecture using jwts and I’m pretty happy with how it turned out. Maybe it is overkill for o
by meling 2y ago
A former student of mine (Vera Yaseneva) redesigned our old auth architecture using jwts and I’m pretty happy with how it turned out. Maybe it is overkill for our simple autograder server, but it was fun getting it to work and I’m sure it is more secure than the old architecture which had many many flaws… it was a maintenance nightmare for years. After the redesign it has been a breeze. Here is the project https://github.com/quickfeed/quickfeed https://github.com/quickfeed/quickfeed
The security arch is mainly in web/auth and web/interceptor packages if anyone is interested in learning from the code. It uses connectrpc, which has a nice interceptor arch.
Happy to share Vera’s thesis report if anyone is interested…
- hu3 2y agoThank you for sharing! I took a look at the code. Looks clean. Please share her thesis. I'm interested.
- meling 2y agoHere it is https://uis.brage.unit.no/uis-xmlui/bitstream/handle/11250/3022596/no.uis%3ainspera%3a92613534%3a6420238.pdf?sequence=1&isAllowed=y https://uis.brage.unit.no/uis-xmlui/bitstream/handle/11250/3...
- hu3 2y agoThank you! I'm looking to write a paper about a software I'm developing and this will help immensely since it's a fitting format.