ModeSizeName
-rw-r--r--2204README-auth.md
-rw-r--r--3343README-build-bsds.md
-rw-r--r--2141README-build-windows.md
-rw-r--r--1231README-gitolite-hook.md
-rw-r--r--4424README-platform-naming.md
-rw-r--r--3339README-resource-management.md
-rw-r--r--4013README-sai-jig.md
-rw-r--r--2812README-sai-json.md
-rw-r--r--5095README-sai-power.md
-rw-r--r--23804README-systemd-nspawn.md
-rw-r--r--109316sai-build-test-flow.png
-rw-r--r--104850sai-embedded-test.png
-rw-r--r--106610sai-ov2.png
-rw-r--r--268612sai-overview.png
-rw-r--r--99164sai-resources.png
READMEs/README-auth.md

Sai web auth

Authorization Overview

Sai uses signed JWTs

There's no UI at the moment for creating authorized users, everything except event deletion and task restart works without authorization.

sai-server configuration for auth

In the vhosts|ws-protocols|com-warmcat-sai section of the config JSON, the following entries define the authorization operation

           "jwt-auth-alg":         "ES512",
           "jwt-auth-jwk-path":    "/etc/sai/server/auth.jwk",
           "jwt-iss":              "com.warmcat",
           "jwt-aud":              "https://libwebsockets.org/sai",

The jwt-iss and jwt-aud values go into generated JWTs and are confirmed to match when receiving a JWT, these define the issuing authority and the "audience", the receipient the JWT was created to be consumed by... the audience should be the globally unique site base URI.

Creating the server JWK

If you build lws with -DLWS_WITH_GENCRYPTO=1 -DLWS_WITH_JOSE=1 -DLWS_WITH_MINIMAL_EXAMPLES=1 it will create a set of JOSE utilities, including one for JWK key generation.

Use this as below to create the server JWK used for signing and validation, for ES512 algorithm in our case

$ sudo ./bin/lws-crypto-jwk -t EC -b512 -vP-521 --alg ES512 > /etc/sai/server/auth.jwk

Defining an authorized user

Sai-server creates a separate auth database and prepares the table schema in it on startup if not already existing. So you using sai-server at all already did most of the work.

To create a user that can login via his browser and see and use the UI for the additional actions, currently you can create the user by hand on the server:

# sqlite3 /home/srv/sai/sai-server-auth.sqlite3
SQLite version 3.32.3 2020-06-18 14:00:33
Enter ".help" for usage hints.
sqlite> .schema
CREATE TABLE auth (_lws_idx integer, name varchar, passphrase varchar, since integer primary key autoincrement, last_updated integer);
CREATE TABLE sqlite_sequence(name,seq);
sqlite> insert into auth (_lws_idx, name, passphrase) values (0, "your@email.com", "somepassword");

Afterwards, it should be possible to log in from the web UI using the given credentials and see the additional UI elements.