You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
forgejo/modules
Jack Hay 18de83b2a3
Redesign Scoped Access Tokens (#24767)
## Changes
- Adds the following high level access scopes, each with `read` and
`write` levels:
    - `activitypub`
    - `admin` (hidden if user is not a site admin)
    - `misc`
    - `notification`
    - `organization`
    - `package`
    - `issue`
    - `repository`
    - `user`
- Adds new middleware function `tokenRequiresScopes()` in addition to
`reqToken()`
  -  `tokenRequiresScopes()` is used for each high-level api section
- _if_ a scoped token is present, checks that the required scope is
included based on the section and HTTP method
  - `reqToken()` is used for individual routes
- checks that required authentication is present (but does not check
scope levels as this will already have been handled by
`tokenRequiresScopes()`
- Adds migration to convert old scoped access tokens to the new set of
scopes
- Updates the user interface for scope selection

### User interface example
<img width="903" alt="Screen Shot 2023-05-31 at 1 56 55 PM"
src="https://github.com/go-gitea/gitea/assets/23248839/654766ec-2143-4f59-9037-3b51600e32f3">
<img width="917" alt="Screen Shot 2023-05-31 at 1 56 43 PM"
src="https://github.com/go-gitea/gitea/assets/23248839/1ad64081-012c-4a73-b393-66b30352654c">

## tokenRequiresScopes  Design Decision
- `tokenRequiresScopes()` was added to more reliably cover api routes.
For an incoming request, this function uses the given scope category
(say `AccessTokenScopeCategoryOrganization`) and the HTTP method (say
`DELETE`) and verifies that any scoped tokens in use include
`delete:organization`.
- `reqToken()` is used to enforce auth for individual routes that
require it. If a scoped token is not present for a request,
`tokenRequiresScopes()` will not return an error

## TODO
- [x] Alphabetize scope categories
- [x] Change 'public repos only' to a radio button (private vs public).
Also expand this to organizations
- [X] Disable token creation if no scopes selected. Alternatively, show
warning
- [x] `reqToken()` is missing from many `POST/DELETE` routes in the api.
`tokenRequiresScopes()` only checks that a given token has the correct
scope, `reqToken()` must be used to check that a token (or some other
auth) is present.
   -  _This should be addressed in this PR_
- [x] The migration should be reviewed very carefully in order to
minimize access changes to existing user tokens.
   - _This should be addressed in this PR_
- [x] Link to api to swagger documentation, clarify what
read/write/delete levels correspond to
- [x] Review cases where more than one scope is needed as this directly
deviates from the api definition.
   - _This should be addressed in this PR_
   - For example: 
   ```go
	m.Group("/users/{username}/orgs", func() {
		m.Get("", reqToken(), org.ListUserOrgs)
		m.Get("/{org}/permissions", reqToken(), org.GetUserOrgsPermissions)
}, tokenRequiresScopes(auth_model.AccessTokenScopeCategoryUser,
auth_model.AccessTokenScopeCategoryOrganization),
context_service.UserAssignmentAPI())
   ```

## Future improvements
- [ ] Add required scopes to swagger documentation
- [ ] Redesign `reqToken()` to be opt-out rather than opt-in
- [ ] Subdivide scopes like `repository`
- [ ] Once a token is created, if it has no scopes, we should display
text instead of an empty bullet point
- [ ] If the 'public repos only' option is selected, should read
categories be selected by default

Closes #24501
Closes #24799

Co-authored-by: Jonathan Tran <jon@allspice.io>
Co-authored-by: Kyle D <kdumontnu@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
1 year ago
..
actions Use the type RefName for all the needed places and fix pull mirror sync bugs (#24634) 1 year ago
activitypub Add Chef package registry (#22554) 1 year ago
analyze Implement FSFE REUSE for golang files (#21840) 2 years ago
assetfs Use a general approach to access custom/static/builtin assets (#24022) 1 year ago
auth Use a general approach to access custom/static/builtin assets (#24022) 1 year ago
avatar Improve avatar uploading / resizing / compressing, remove Fomantic card module (#24653) 1 year ago
base Use a general Eval function for expressions in templates. (#23927) 1 year ago
cache Update redis library to support redis v7 (#24114) 1 year ago
charset Update go tool dependencies, restructure lint targets (#24239) 1 year ago
container Implement FSFE REUSE for golang files (#21840) 2 years ago
context Redesign Scoped Access Tokens (#24767) 1 year ago
csv Refactor locale number (#24134) 1 year ago
doctor Rewrite logger system (#24726) 1 year ago
emoji Fix unstable emoji sort (#22346) 2 years ago
eventsource Move `convert` package to services (#22264) 2 years ago
generate Implement FSFE REUSE for golang files (#21840) 2 years ago
git revert the removed method to fix tmpl break on graph page (#25005) 1 year ago
gitgraph Add context cache as a request level cache (#22294) 1 year ago
graceful Improve queue and logger context (#24924) 1 year ago
hcaptcha Consume hcaptcha and pwn deps (#22610) 2 years ago
highlight test_env: hardcode major go version in use (#23464) 1 year ago
hostmatcher Implement FSFE REUSE for golang files (#21840) 2 years ago
html Implement FSFE REUSE for golang files (#21840) 2 years ago
httpcache Use standard HTTP library to serve files (#24693) 1 year ago
httplib Use standard HTTP library to serve files (#24693) 1 year ago
indexer Improve queue and logger context (#24924) 1 year ago
issue/template Allow issue templates to not render title (#22589) 2 years ago
json Update gitea-vet to check FSFE REUSE (#22004) 2 years ago
label Make label templates have consistent behavior and priority (#23749) 1 year ago
lfs Rewrite logger system (#24726) 1 year ago
log Improve logger Pause handling (#24946) 1 year ago
markup Fix video width overflow in markdown, and other changes to match img (#24834) 1 year ago
mcaptcha Implement FSFE REUSE for golang files (#21840) 2 years ago
metrics Use a separate admin page to show global stats, remove `actions` stat (#25062) 1 year ago
migration Scoped labels (#22585) 1 year ago
mirror Improve queue and logger context (#24924) 1 year ago
nosql Update redis library to support redis v7 (#24114) 1 year ago
notification Rename NotifyPullReviewRequest to NotifyPullRequestReviewRequest (#24988) 1 year ago
options Use a general approach to access custom/static/builtin assets (#24022) 1 year ago
packages Add CRAN package registry (#22331) 1 year ago
paginator Use more specific test methods (#24265) 1 year ago
pprof Implement FSFE REUSE for golang files (#21840) 2 years ago
private Use the type RefName for all the needed places and fix pull mirror sync bugs (#24634) 1 year ago
process Do not output "Trace" level logs from process manager by default (#24952) 1 year ago
proxy Use proxy for pull mirror (#22771) 1 year ago
proxyprotocol Implement FSFE REUSE for golang files (#21840) 2 years ago
public Use standard HTTP library to serve files (#24693) 1 year ago
queue Help to recover from corrupted levelqueue (#24912) 1 year ago
recaptcha Implement FSFE REUSE for golang files (#21840) 2 years ago
references Use correct captured group range when parsing cross-reference (#22672) 2 years ago
regexplru Implement FSFE REUSE for golang files (#21840) 2 years ago
repository Refactor INI package (first step) (#25024) 1 year ago
secret Improve decryption failure message (#24573) 1 year ago
session Update redis library to support redis v7 (#24114) 1 year ago
setting Refactor INI package (first step) (#25024) 1 year ago
sitemap Fix sitemap (#22272) 2 years ago
ssh Rewrite logger system (#24726) 1 year ago
storage Implement actions artifacts (#22738) 1 year ago
structs API endpoint for changing/creating/deleting multiple files (#24887) 1 year ago
svg Use a general approach to access custom/static/builtin assets (#24022) 1 year ago
sync Implement FSFE REUSE for golang files (#21840) 2 years ago
system Implement FSFE REUSE for golang files (#21840) 2 years ago
templates Remove the service worker (#25010) 1 year ago
test Fix admin config page error, use tests to cover the admin config and 500 error page (#24965) 1 year ago
testlogger Rewrite logger system (#24726) 1 year ago
timeutil Fix incorrect webhook time and use relative-time to display it (#24477) 1 year ago
translation Refactor INI package (first step) (#25024) 1 year ago
turnstile Add new captcha: cloudflare turnstile (#22369) 1 year ago
typesniffer Do not recognize text files as audio (#23355) 1 year ago
updatechecker Implement FSFE REUSE for golang files (#21840) 2 years ago
upload Implement FSFE REUSE for golang files (#21840) 2 years ago
uri Implement FSFE REUSE for golang files (#21840) 2 years ago
user Implement FSFE REUSE for golang files (#21840) 2 years ago
util Rewrite logger system (#24726) 1 year ago
validation Map OIDC groups to Orgs/Teams (#21441) 1 year ago
web Fix install page context, make the install page tests really test (#24858) 1 year ago
webhook New webhook trigger for receiving Pull Request review requests (#24481) 1 year ago