Repository navigation
Cognito Auth integration - #5745
MartinTechy wants to merge 20 commits into
Conversation
✅ Deploy Preview for redwoodjs-docs ready!
To edit notification comments on pull requests, go to your Netlify site settings. |
|
A few questions for the maintainers :
|
|
@MartinTechy thanks for your work! 💪 . I'm glad to see someone put in the effort to finish this feature. Let me know if you need any support on some of the missing features. 🚀 |
|
Thank you @MartinTechy for taking this to the finish line! Perfect timing! My project requires AWS Cognito as well, so I'll be helping you finish this. For your earlier question:
I ran into the same problem when trying to handle the AWS side of the SDK. There's a handful additional convenient functions that the AWS SDK exposes, but the Redwood doesn't account for in it's AuthClient interface. So I did some digging on who worked on the resetPassword,forgotPassword,validateResetToken part of the AuthClient interface, since it's right up our alley for the AWS Cognito Auth SDK, and it was our favorite @cannikin while working on dbAuth. I did some more digging and found an insightful thread regarding this.
TLDR: We should grab the AWS client directly from {client} =useAuth() and directly call the relevant functions in our components. If dbAuth ever updates itself with more auth logic, we can start refactoring. I vote for bypassing RW's Authclient interface for using all of the extra little features in AWS Cognito. |
|
@Leon-Sam Thanks for your inputs !
I was slowly coming to the same conclusion. The basic functionality is there and we give the user a way to implement the more complex cases. IMO as long as we document it correctly it will be fine. Do you have an opinion on managing the roles with the Cognito user groups ? It felt like the easiest and most straightforward way to add role support |
|
I might need some help to fix these tests. I spent some time trying to find were these |
|
Sound like a plan. Here's my current to-do list. Work is a little busy right now, but I plan on getting to this over the weekend. If your waiting on me for this, feel free to get ahead and I'll pull down any updates
Edit: For the roles: I haven't got to thinking about that yet. I'll report back once I have better grasp on the api side |
# Conflicts: # yarn.lock
|
I just added the JWT verification on the API side so I think I'll open the PR for review as I estimate that it is ready feature wise. I was also thinking about creating a post on the forum about the tests breaking to reach more people.
That's what I have for now, maybe it'll help someone to find the issue |
|
Hey MartinTechy, Work made a change on our Redwood project; and we switched auth providers. (Azure AD B2C); I spent my weekend adding compatibility for that. #5781 I'm going to spend my "open source time" to take that one to the finish line. Once that is done, I'll circle back here and help you close this out. This might take a couple weeks on my end. |
# Conflicts: # docs/docs/authentication.md # packages/auth/package.json # yarn.lock
|
Hi Martin if I can give you a hand please let me know. My branch had most of the functionality except the decoder. |
|
@ManavDia I think the only missing piece is this failing test so if you have an idea why it's failing I would take it 😅 Someone on the Discourse mentioned that @dthyresson should be able to help troubleshoot |
# Conflicts: # packages/auth/package.json # yarn.lock
|
Hey @MartinTechy. Super stoked by the collaboration happening in this thread! @ManavDia I saw your PR too. There has been and still is some real interest around integrating cognito auth, and we've yet to get back to you, so thanks for your patience and persistence! We just discussed this PR and a few others that add auth providers today. Redwood already has quite a few auth providers, and as we add more, the cost of maintaining them all is in the back of our minds. A post-v1 goal of ours was to decouple auth. We haven’t made headway on it yet, cause other things (many other things), but given the activity around this PR, we’re going to prioritize figuring out what "decoupling auth" would mean this week. I.e. exactly how much work is it, and once we know that, when could we get it done? If it turns out that decoupling auth is months of work, we’ll prioritize getting this one in. But if we think we can do it soon, we’re going to ask you to wait till we’ve got that figured out. But we've kept you in suspense long enough so we're timeboxing ourselves a bit: we'll let you know by ~next week. Till then you're welcome to continue working on this one, or you can wait till you hear back from us. Thanks for taking the time to contribute! |
|
Hi @jtoar, thanks for your message ! I have no problem waiting a few days for the decision about decoupling. I think that except for this failing test, all the work needed is done on this PR. But let me know if I missed something ! |
|
Hey @MartinTechy, thanks for your patience! We’ve done the preliminary work around decoupling auth. The team feels good about it, so we’re going to move ahead with that. But instead of asking you to just wait for us to finish, we’d like to invite you to collaborate with us on this. No pressure—totally optional! And while we’re still working out all the details, we think that this would mean the following:
I'm sure you still have questions, but are you open to trying something like that out? Let us know and we'll circle back when we have it all ironed out. |
|
Hey @jtoar , I would love to be part of that project and the discussions around it ! Just let me know what I can do |
|
Hi @jtoar, Is there any update on this ? |
|
Hi @MartinTechy The web/front-end part of it is in pretty good shape. I'm currently working on the setup scripts. I don't like doing estimates, because it always just leave people feeling disappointed. But do check back in about a week or so and see how far along we are on #5985. As soon as it's merged into main it would be great if we could get some help validating our new implementation by having someone like you try to implement a new auth provider as an external package 🙏 |
@Tobbe Thank you for your quick answer ! I didn't see this PR so I'll keep an eye on it. I'll definitely be in to try to implement the Cognito auth with this new system. Let me know if you need some help in the meantime |
|
@MartinTechy just a notice that #5985 has been merged, should you be ready to move this forward, there is interest 👍🏻 |
@noire-munich Yes just saw that the other day. I was thinking that it would be better to wait for the official release before working on it but maybe that's not the right approach. @Tobbe what do you think about this ? Is everything ready to start on new implementations ? |
|
I feel like the api is pretty stable. So you could totally get started if you wanted. |
What @Tobbe says 👍🏻 |
|
In that case I will wait for the official release and use the same implementation as the other packages (and do the migration later if needed). |
|
I'm cleaning up our PRs in preparation for the next major version of RW. This one seems to have gone stale, so I'm going to close it. If anyone is still interested in working on this feature or if there are any unresolved issues, please feel free to:
Let's keep the collaboration going 🚂 If you have any questions or need assistance, don't hesitate to reach out. Thanks again for the contributions 🙏 |
Cognito Integration for Redwood
This PR aims to add a new Cognito Auth integration.
I wanted to use AWS Cognito for my project but saw there was no integration yet.
After seeing that #3562 was abandoned and that I was not the only one wanting to use Cognito for Authentication I decided to take the matter in my own hands.
This PR takes a lot of @josuablejeru's work and adds the missing pieces. So big thanks for the initial work !
How it will work
yarn rw setup auth cognitoCOGNITO_USERPOOL_IDandCOGNITO_CLIENT_IDto your .env fileRBAC is based on the the Cognito user groups without IAM Roles
Missing pieces
What's left to do :
forgotPasswordimplementationresetPasswordimplementationFeel free to comment if I'm missing something