Technical Details
Update the documentation and src/lib/server/aws/vars.ts. Add an endpoint in /(api)/support/[id=uuid]/token? (need to add uuid route params filter as well)
Summary
We are adding a new role to Scriptoria: Support Agent. In Scriptoria, the Support Agent will be creating SupportData requests. These requests will use a uuid as the id of the request. The reason for this is that we want to be able to pass along a URL to and end-user that is not guessable. They will be entering the URL into Scripture App Builder, which will send a request to Scriptoria to retrieve a federated token with write access to a S3 Bucket + path (based on the SupportData request id). This will be an unauthenticated request since the end-user is not a Scriptoria user. Scriptoria will make an API call to BuildEngine (this project) to do the work of generating the federated token (since all interaction with AWS is done by BuildEngine). This will be similar to how BuildEngine creates a federated token for project upload/download.
We will also need to support creating a read token for the Support Agent. In Scriptoria, this will be an authenticated request, only allowed by Support Agents (and Super Users). Scriptoria will make an API call to BuildEngine to do the work of generating the federated token for reading.
Technical Details
Update the documentation and
src/lib/server/aws/vars.ts. Add an endpoint in/(api)/support/[id=uuid]/token? (need to add uuid route params filter as well)Summary
We are adding a new role to Scriptoria: Support Agent. In Scriptoria, the Support Agent will be creating SupportData requests. These requests will use a uuid as the id of the request. The reason for this is that we want to be able to pass along a URL to and end-user that is not guessable. They will be entering the URL into Scripture App Builder, which will send a request to Scriptoria to retrieve a federated token with write access to a S3 Bucket + path (based on the SupportData request id). This will be an unauthenticated request since the end-user is not a Scriptoria user. Scriptoria will make an API call to BuildEngine (this project) to do the work of generating the federated token (since all interaction with AWS is done by BuildEngine). This will be similar to how BuildEngine creates a federated token for project upload/download.
We will also need to support creating a read token for the Support Agent. In Scriptoria, this will be an authenticated request, only allowed by Support Agents (and Super Users). Scriptoria will make an API call to BuildEngine to do the work of generating the federated token for reading.