|
5 | 5 |
|
6 | 6 | Dataall's SDK requires user profile information to be stored either in a local file or in AWS Secrets Manager. The user information required includes: |
7 | 7 |
|
8 | | -- auth_type: Either `CognitoAuth` or `CustomAuth` |
| 8 | +- auth_type: `CognitoAuth`, `CustomAuth` or `OidcBrowserAuth` (browser login, no password) |
9 | 9 | - client_id: The App Client ID |
10 | 10 | - api_endpoint_url: The URL data.all API Gateway Endpoint |
11 | | -- redirect_uri: The data.all domain URL |
12 | | -- idp_domain_url: The Identity Providers URL |
| 11 | +- redirect_uri: The data.all domain URL (for `OidcBrowserAuth`: the loopback URI registered for the client, default `http://localhost:8765/callback`) |
| 12 | +- idp_domain_url: The Identity Providers URL (for `OidcBrowserAuth`: the OIDC issuer URL) |
13 | 13 | - client_secret (optional): The client secret used for the data.all App Client |
14 | 14 | - auth_server (optional, used for CustomAuth): The Custom Authorization Server used if applicable |
15 | 15 | - session_token_endpoint (optional, required for CustomAuth): The Identity Provider API endpoint to retrieve session tokens |
| 16 | +- scopes (optional, OidcBrowserAuth): OIDC scopes, default `openid offline_access` |
| 17 | +- fallback_redirect_uri (optional, OidcBrowserAuth): second loopback URI tried when the first port is busy |
| 18 | +- frontend_url (optional): the data.all UI URL, sent as `Origin` and `Referer` headers; required where the API only accepts calls carrying the UI origin |
16 | 19 | - profile: The Profile Name |
17 | 20 |
|
18 | 21 | Data.all's SDK uses the profile information to fetch and save tokens from the data.all application. |
19 | 22 |
|
20 | 23 | By default the user information is provided at `~/.dataall/config.yaml` and the token information is saved at `~/.dataall/credentials.yaml` |
21 | 24 |
|
22 | | -If a valid token or refresh token exists for the given user, that will be used to fetch a new token and authenticate the profile. Otherwise, the user will be prompted for username and password when running an API request and the fetched tokens will be saved. |
| 25 | +If a valid token or refresh token exists for the given user, that will be used to fetch a new token and authenticate the profile. Otherwise, the user will be prompted for username and password when running an API request and the fetched tokens will be saved. With `OidcBrowserAuth` the SDK opens the identity provider's login page in the browser instead (or prints a device code on hosts without a browser). |
23 | 26 |
|
24 | 27 |
|
25 | 28 | ### Configuring your first data.all User profile |
@@ -49,6 +52,20 @@ TestCustomProfile: |
49 | 52 | session_token_endpoint: testtokenendpoint |
50 | 53 | ``` |
51 | 54 |
|
| 55 | + |
| 56 | +### Connecting with just the front page URL |
| 57 | + |
| 58 | +You do not have to write a profile by hand. Point the client at the data.all front page and the SDK reads the authentication type, identity provider, client id and API endpoint from the deployed application: |
| 59 | + |
| 60 | +```py3 |
| 61 | +import dataall_sdk as dataall |
| 62 | + |
| 63 | +client = dataall.client(dataall_url="https://DATAALL_DOMAIN_URL") |
| 64 | +client.list_organizations() |
| 65 | +``` |
| 66 | + |
| 67 | +The discovered profile is saved in `~/.dataall/config.yaml` under the page's host name (pass `profile="..."` to choose the name), so the next call reuses it without contacting the front page, and the tokens are kept in `credentials.yaml` as for any other profile. If a profile with that name already exists it is used as is. For OIDC deployments the first API call opens the browser for the login; the identity provider app must allow the loopback redirect URIs (`http://localhost:8765/callback` and `http://localhost:8766/callback`). Values that cannot be read from the page raise `MissingParametersException` naming them. |
| 68 | + |
52 | 69 | ### Specifying your user profile |
53 | 70 |
|
54 | 71 | Once you have configured your user profile appropriately, you can begin running data.all API requests via the SDK using your configured profile(s) such as: |
|
0 commit comments