-
Notifications
You must be signed in to change notification settings - Fork 86
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[WIP]Add Guild Wars 2 Oauth authentification #163
Conversation
This adds the OAuth2 authentification by Guild Wars 2 (and changes some defaults to be more sensible for testing environments). TODOs: - get profile information from the GW2 API - add a nice picture for the login button
Cool, Maybe no need to store it until it's actually necessary, |
The user profile is now build from the API data. Since it does not provide any email info, it is built as "[email protected]"... Not sure if we should do anything else... Also fix some things in the OAuth2Client...
Technically this should be finished. I still need to add an icon for the button though. I'm also waiting for an answer on arenanet/api-cdi#21 (which is now closed) in case I need some more changes. And since the authorization is still BETA quality, I'd wait to merge this in anyways :) |
Revert a change in the OAuth library while adding the possibility to add additional headers to single calls. Also log full request details if logging is on. Also use the new "additional header" parameter in the GuildWars provider I didn't add an image to the guild wars 2 button, because I don't know how...
Should be done now, except:
|
okay, I'll try to free up some time this week to take a look at it and test it :) |
Hrm... https://forum-en.guildwars2.com/forum/community/api/Launching-v2-account-w-Authentication/4981219 pretty much kills this PR 💥 But lets wait and see first |
awh :/ ... I was under the asumption this was ready to be merged? |
It was, until I asked whether the OAuth is still in Beta, because it already appeared in the accounts listing. Then they dropped the ball about movements away from OAuth2 towards API-style keys. See my question https://forum-en.guildwars2.com/forum/community/api/Launching-v2-account-w-Authentication/4971293 and the following discussion |
any updates? |
Nothing specific. The new authenitcation method will be revealed "within weeks" with a proposed migration strategy. So I'd still like to wait. |
🌋 See https://forum-en.guildwars2.com/forum/community/api/HEADS-UP-OAuth2-being-replaced-next-week tl;dr: No new OAuth apps can be registered, authentication is out of the window, user has to do the "create token" step of OAuth manually (which doubled as authentication), http header stays the same. So maybe it's possible to reuse parts of this, but overall it seems to become pretty complicated for normal users to grant access to private parts of the API. |
This adds the OAuth2 authentification by Guild Wars 2 (and changes some defaults
to be more sensible for testing environments).
TODOs:
This PR serves 2 purposes:
Question: I am debating whether to save the access and refresh tokens with expiry date, because ANet plans features to the API that might be interesting to gw2spidy as well (Bank/character inventory, TP history). Soo...
That's it for now, if I get more ideas/questions, I'll ask.