diff --git a/.gitignore b/.gitignore index f2afccf..c795954 100644 --- a/.gitignore +++ b/.gitignore @@ -4,6 +4,8 @@ /live .rvmrc +dist/* + ## TEXTMATE *.tmproj tmtags diff --git a/README.markdown b/README.markdown index 6b5ce24..5e49bfa 100644 --- a/README.markdown +++ b/README.markdown @@ -1,8 +1,8 @@ -# OmniAuth +# OmniAuth: Standardized Multi-Provider Authentication I know what you're thinking: yes, it's yet **another** authentication solution for Rack applications. But we're going to do things a little bit differently this time. OmniAuth is built from the ground up on the philosophy that **authentication is not the same as identity**. OmniAuth is based on two observations: -1. The traditional 'sign up using a login and password' model is becoming the exception, not the rule. Modern web applications offer external authentication via OpenID, Facebook, and OAuth. +1. The traditional 'sign up using a login and password' model is becoming the exception, not the rule. Modern web applications offer external authentication via OpenID, Facebook, and/or OAuth. 2. The interconnectable web is no longer a dream, it is a necessity. It is not unreasonable to expect that one application may need to be able to connect to one, three, or twelve other services. Modern authentication systems should a user's identity to be associated with many authentications. ## Theoretical Framework @@ -15,4 +15,80 @@ In the Request Phase, we *request* information from the user that is necessary t ### The Callback Phase -In the Callback Phase, we receive an authenticated **unique identifier** that can differentiate this user from other users of the same authentication system. Additionally, we may provide **user information** that can be automatically harvested by the application to fill in the details of the authenticating user. \ No newline at end of file +In the Callback Phase, we receive an authenticated **unique identifier** that can differentiate this user from other users of the same authentication system. Additionally, we may provide **user information** that can be automatically harvested by the application to fill in the details of the authenticating user. + +## Practical Implementation + +In practical terms, OmniAuth is a collection of Rack middleware, each of which represent an **authentication provider**. The officially maintained providers are: + +* Password (simple SHA1 encryption) +* OpenID +* OAuth + * Twitter + * LinkedIn +* OpenID +* Facebook + +These middleware all follow a consistent pattern in that they initiate the **request phase** when the browser is directed (with additional information in some cases) to `/auth/provider_name`. They then all end their authentication process by calling the main Rack application at the endpoint `/auth/provider_name/callback` with request parameters pre-populated with an `auth` hash containing: + +* `'provider'` - The provider name +* `'uid'` - The unique identifier of the user +* `'credentials'` - A hash of credentials for access to protected resources from the authentication provider (OAuth, Facebook) +* `'user_info'` - Additional information about the user + +What this means is that, for all intents and purposes, your application needs only be concerned with *directing the user to the requesst phase* and *managing user information and session upon authentication callback*. All of the implementation details of the different authentication providers can be treated as a black box. + +## Examples + +### An Authentication Hash + + params['auth'] = { + 'provider' => 'Twitter', + 'uid' => '1234567', + 'credentials => { + 'token' => 'abc', + 'secret' => 'def' + }, + 'user_info' => { + 'name' => 'Michael Bleigh', + 'nickname' => 'mbleigh', + 'location' => 'Canton, MI', + 'image' => 'http://aws.twitter.com/...', + 'urls' => {'Website' => 'http://www.mbleigh.com/'} + }, + 'extra' => { + 'twitter_user' => { + 'id' => 1234567, + 'screen_name' => 'mbleigh' + # ... + } + } + } + +### Sinatra + + require 'rubygems' + require 'sinatra' + require 'omniauth' + require 'openid/store/filesystem' + + use OmniAuth::Builder do + provider :open_id, OpenID::Store::Filesystem.new('/tmp') + provider :twitter, 'consumerkey', 'consumersecret' + end + + get '/' do + <<-HTML + Sign in with Twitter + +
+ + +
+ HTML + end + + get '/auth/:name/callback' do + auth = params['auth'] + # do whatever you want with the information! + end \ No newline at end of file diff --git a/oa-basic/Rakefile b/oa-basic/Rakefile index 96438b6..515879f 100644 --- a/oa-basic/Rakefile +++ b/oa-basic/Rakefile @@ -1,6 +1,9 @@ require 'rubygems' require 'rake' +require 'mg' +MG.new('oa-basic.gemspec') + require 'spec/rake/spectask' Spec::Rake::SpecTask.new(:spec) do |spec| spec.libs << '../oa-core/lib' << 'lib' << 'spec' diff --git a/oa-basic/VERSION b/oa-basic/VERSION new file mode 100644 index 0000000..8a9ecc2 --- /dev/null +++ b/oa-basic/VERSION @@ -0,0 +1 @@ +0.0.1 \ No newline at end of file diff --git a/oa-basic/oa-basic.gemspec b/oa-basic/oa-basic.gemspec new file mode 100644 index 0000000..1a2e634 --- /dev/null +++ b/oa-basic/oa-basic.gemspec @@ -0,0 +1,21 @@ +version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip + +Gem::Specification.new do |gem| + gem.name = "oa-basic" + gem.version = version + gem.summary = %Q{HTTP Basic strategies for OmniAuth.} + gem.description = %Q{HTTP Basic strategies for OmniAuth.} + gem.email = "michael@intridea.com" + gem.homepage = "http://github.com/intridea/omni_auth" + gem.authors = ["Michael Bleigh"] + + gem.files = Dir.glob("{lib}/**/*") + %w(README.rdoc LICENSE.rdoc CHANGELOG.rdoc) + + gem.add_dependency 'oa-core', "~> #{version.gsub(/\d$/,'0')}" + gem.add_dependency 'restclient' + + gem.add_development_dependency "rspec", ">= 1.2.9" + gem.add_development_dependency "webmock" + gem.add_development_dependency "rack-test" + gem.add_development_dependency "mg" +end \ No newline at end of file diff --git a/oa-core/Rakefile b/oa-core/Rakefile index 4cd514a..e855c63 100644 --- a/oa-core/Rakefile +++ b/oa-core/Rakefile @@ -1,6 +1,9 @@ require 'rubygems' require 'rake' +require 'mg' +MG.new('oa-core.gemspec') + require 'spec/rake/spectask' Spec::Rake::SpecTask.new(:spec) do |spec| spec.libs << 'lib' << 'spec' diff --git a/oa-core/VERSION b/oa-core/VERSION new file mode 100644 index 0000000..8a9ecc2 --- /dev/null +++ b/oa-core/VERSION @@ -0,0 +1 @@ +0.0.1 \ No newline at end of file diff --git a/oa-core/oa-core.gemspec b/oa-core/oa-core.gemspec new file mode 100644 index 0000000..fdfe91a --- /dev/null +++ b/oa-core/oa-core.gemspec @@ -0,0 +1,18 @@ +Gem::Specification.new do |gem| + gem.name = "oa-basic" + gem.version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip + gem.summary = %Q{HTTP Basic strategies for OmniAuth.} + gem.description = %Q{HTTP Basic strategies for OmniAuth.} + gem.email = "michael@intridea.com" + gem.homepage = "http://github.com/intridea/omni_auth" + gem.authors = ["Michael Bleigh"] + + gem.files = Dir.glob("{lib}/**/*") + %w(README.rdoc LICENSE.rdoc CHANGELOG.rdoc) + + gem.add_dependency 'rack' + + gem.add_development_dependency "rspec", ">= 1.2.9" + gem.add_development_dependency "webmock" + gem.add_development_dependency "rack-test" + gem.add_development_dependency "mg" +end \ No newline at end of file diff --git a/oa-core/spec/omniauth/builder_spec.rb b/oa-core/spec/omniauth/builder_spec.rb new file mode 100644 index 0000000..33cfac9 --- /dev/null +++ b/oa-core/spec/omniauth/builder_spec.rb @@ -0,0 +1,20 @@ +require File.dirname(__FILE__) + '/../spec_helper' + +describe OmniAuth::Builder do + describe '#provider' do + it 'should translate a symbol to a constant' do + OmniAuth::Strategies.should_receive(:const_get).with('MyStrategy').and_return(Class.new) + OmniAuth::Builder.new(nil) do + provider :my_strategy + end + end + + it 'should also just accept a class' do + class ExampleClass; end + + lambda{ OmniAuth::Builder.new(nil) do + provider ExampleClass + end }.should_not raise_error + end + end +end \ No newline at end of file diff --git a/oa-oauth/CHANGELOG.rdoc b/oa-oauth/CHANGELOG.rdoc new file mode 100644 index 0000000..bd9a2f2 --- /dev/null +++ b/oa-oauth/CHANGELOG.rdoc @@ -0,0 +1,5 @@ += Changelog + +== 0.0.1 + +* Initial release! \ No newline at end of file diff --git a/oa-oauth/LICENSE.rdoc b/oa-oauth/LICENSE.rdoc new file mode 100644 index 0000000..6428a77 --- /dev/null +++ b/oa-oauth/LICENSE.rdoc @@ -0,0 +1,19 @@ +Copyright (c) 2010 Michael Bleigh, Intridea Inc. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. \ No newline at end of file diff --git a/oa-oauth/README.rdoc b/oa-oauth/README.rdoc new file mode 100644 index 0000000..e69de29 diff --git a/oa-oauth/Rakefile b/oa-oauth/Rakefile index 96438b6..1fb9b47 100644 --- a/oa-oauth/Rakefile +++ b/oa-oauth/Rakefile @@ -1,6 +1,9 @@ require 'rubygems' require 'rake' +require 'mg' +MG.new('oa-oauth.gemspec') + require 'spec/rake/spectask' Spec::Rake::SpecTask.new(:spec) do |spec| spec.libs << '../oa-core/lib' << 'lib' << 'spec' diff --git a/oa-oauth/VERSION b/oa-oauth/VERSION new file mode 100644 index 0000000..8a9ecc2 --- /dev/null +++ b/oa-oauth/VERSION @@ -0,0 +1 @@ +0.0.1 \ No newline at end of file diff --git a/oa-oauth/oa-oauth.gemspec b/oa-oauth/oa-oauth.gemspec index 065772e..94fca59 100644 --- a/oa-oauth/oa-oauth.gemspec +++ b/oa-oauth/oa-oauth.gemspec @@ -1,18 +1,23 @@ -require 'omniauth/version' +version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip Gem::Specification.new do |gem| gem.name = "oa-oauth" - gem.version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.trim + gem.version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip gem.summary = %Q{OAuth strategies for OmniAuth.} gem.description = %Q{OAuth strategies for OmniAuth.} gem.email = "michael@intridea.com" gem.homepage = "http://github.com/intridea/omni_auth" gem.authors = ["Michael Bleigh"] - gem.add_dependency 'oa-core' + gem.files = Dir.glob("{lib}/**/*") + %w(README.rdoc LICENSE.rdoc CHANGELOG.rdoc) + + gem.add_dependency 'oa-core', "~> #{version.gsub(/\d$/,'0')}" gem.add_dependency 'oauth' gem.add_dependency 'nokogiri' gem.add_dependency 'json' gem.add_development_dependency "rspec", ">= 1.2.9" + gem.add_development_dependency "webmock" + gem.add_development_dependency "rack-test" + gem.add_development_dependency "mg" end \ No newline at end of file diff --git a/oa-openid/Rakefile b/oa-openid/Rakefile index 96438b6..e210e56 100644 --- a/oa-openid/Rakefile +++ b/oa-openid/Rakefile @@ -1,6 +1,9 @@ require 'rubygems' require 'rake' +require 'mg' +MG.new('oa-openid.gemspec') + require 'spec/rake/spectask' Spec::Rake::SpecTask.new(:spec) do |spec| spec.libs << '../oa-core/lib' << 'lib' << 'spec' diff --git a/oa-openid/VERSION b/oa-openid/VERSION new file mode 100644 index 0000000..8a9ecc2 --- /dev/null +++ b/oa-openid/VERSION @@ -0,0 +1 @@ +0.0.1 \ No newline at end of file diff --git a/oa-openid/oa-openid.gemspec b/oa-openid/oa-openid.gemspec new file mode 100644 index 0000000..185ab8c --- /dev/null +++ b/oa-openid/oa-openid.gemspec @@ -0,0 +1,21 @@ +version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip + +Gem::Specification.new do |gem| + gem.name = "oa-openid" + gem.version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip + gem.summary = %Q{OpenID strategies for OmniAuth.} + gem.description = %Q{OpenID strategies for OmniAuth.} + gem.email = "michael@intridea.com" + gem.homepage = "http://github.com/intridea/omni_auth" + gem.authors = ["Michael Bleigh"] + + gem.files = Dir.glob("{lib}/**/*") + %w(README.rdoc LICENSE.rdoc CHANGELOG.rdoc) + + gem.add_dependency 'oa-core', "~> #{version.gsub(/\d$/,'0')}" + gem.add_dependency 'rack-openid' + + gem.add_development_dependency "rspec", ">= 1.2.9" + gem.add_development_dependency "webmock" + gem.add_development_dependency "rack-test" + gem.add_development_dependency "mg" +end \ No newline at end of file diff --git a/oa-rails/Rakefile b/oa-rails/Rakefile deleted file mode 100644 index 96438b6..0000000 --- a/oa-rails/Rakefile +++ /dev/null @@ -1,10 +0,0 @@ -require 'rubygems' -require 'rake' - -require 'spec/rake/spectask' -Spec::Rake::SpecTask.new(:spec) do |spec| - spec.libs << '../oa-core/lib' << 'lib' << 'spec' - spec.spec_files = FileList['spec/**/*_spec.rb'] -end - -task :default => :spec \ No newline at end of file diff --git a/omniauth/Rakefile b/omniauth/Rakefile new file mode 100644 index 0000000..bbcb2b0 --- /dev/null +++ b/omniauth/Rakefile @@ -0,0 +1,5 @@ +require 'rubygems' +require 'rake' + +require 'mg' +MG.new('omniauth.gemspec') \ No newline at end of file diff --git a/omniauth/omniauth.gemspec b/omniauth/omniauth.gemspec new file mode 100644 index 0000000..1c21908 --- /dev/null +++ b/omniauth/omniauth.gemspec @@ -0,0 +1,23 @@ +version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip + +Gem::Specification.new do |gem| + gem.name = "omniauth" + gem.version = File.open(File.dirname(__FILE__) + '/VERSION', 'r').read.strip + gem.summary = %Q{Rack middleware for standardized multi-provider authentication.} + gem.description = %Q{OmniAuth is an authentication framework that that separates the concept of authentiation from the concept of identity, providing simple hooks for any application to have one or multiple authentication providers for a user.} + gem.email = "michael@intridea.com" + gem.homepage = "http://github.com/intridea/omni_auth" + gem.authors = ["Michael Bleigh"] + + gem.files = Dir.glob("{lib}/**/*") + %w(README.rdoc LICENSE.rdoc CHANGELOG.rdoc) + + gem.add_dependency 'oa-core', "~> #{version.gsub(/\d$/,'0')}" + gem.add_dependency 'oa-oauth', "~> #{version.gsub(/\d$/,'0')}" + gem.add_dependency 'oa-basic', "~> #{version.gsub(/\d$/,'0')}" + gem.add_dependency 'oa-openid', "~> #{version.gsub(/\d$/,'0')}" + + gem.add_development_dependency "rspec", ">= 1.2.9" + gem.add_development_dependency "webmock" + gem.add_development_dependency "rack-test" + gem.add_development_dependency "mg" +end \ No newline at end of file