Skip to content

Design: tokens without a refresh token, duplicating connectors and tools, per-connector export - #963

Draft
keysersoft wants to merge 1 commit into
mainfrom
keysersoft/design-token-grants-duplication
Draft

keysersoft wants to merge 1 commit into
mainfrom
keysersoft/design-token-grants-duplication

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

Design document only, no code. It analyses two requests from custom REST connector users, plus a related bug, so the implementation can start from an agreed plan:

  1. APIs that issue short-lived tokens with no refresh token (OAuth2 password grant, e.g. Datto RMM with 100-hour tokens; Keycloak client credentials). Today these connectors stop working when the token expires.
    • Options: a password grant in the token service, a grant selector in the OAuth2 forms (client_credentials already works in the engine but can't be chosen in the UI), a form-encoded body for Login → Token.
  2. Duplicating a tool or a connector, and exporting or importing a single connector with collision handling.
    • Also: connector variables already remove the need to repeat auth parameters in every tool.
  3. Related bug: the connector edit form shows saved auth settings as empty and overwrites them when the secret is retyped.

The suggested order of work is at the end of docs/design/token-grants-and-connector-duplication.md.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant