hardik.handa

hardik.handa

Planning on integrating with a client which accepts Oauth2 client credential based Token. The token validity is 1 day for now ( must mention that the client is completely internal and has no access to internet ).
Now there are two approaches that I am seeing fit:

  1. Either call for oauth token as a plug before every call to that client, fetch the token ( Seems like an overkill to be doing before every call to that client.
  2. Fetch the client token once everyday or whenever a new node is getting spun up, and then store it somehow as a state and then fetch the token just internally from that state everytime we have to call that client, if we get 401 on any call from the client, we reset the state, so that it leads to fetching of the token again.

Now I am not sure, should we be using GenServer for this or should we use Memoize for this. Any help or suggestion is more than welcome.

Thanks

Showing Posts 1 to 2

tangui

tangui

Calling the authorization server (AS) every time is indeed not performant, and it might even lead to some problems:

  • if the AS discards the former access tokens (ATs), you might have an in-flight request hitting the target API with an already invalidated AT
  • otherwise you’ll flood the AS with new ATs to store, and you might hit some limits

GenServer is a good fit for this problem (compared with ETS) because, even though request go through GenServer sequentially, you’re assured that in case the AT is expired, the first request hitting the GenServer will trigger token renewal and the others will just wait without requesting new ATs as well. Although if you have a very high number of processes making API requests, you might hit a bottleneck compared with ETS.

Note that some ASes only support 1 AT per client. If you’ve a multinode deployment, that might be a problem.

If you’re using Tesla, you could even write a middleware dealing with detecting expired tokens, requesting a new one when receiving an invalid_token error code (from RFC6750 - 3.1. Error Codes) and replaying the unauthorized request.

If the AS you’re using requires a complex client authentication scheme, you can take a look at TeslaOAuth2ClientAuth that implement some.

hardik.handa

hardik.handa OP

Thanks that really helps to bring perspective.
As I am new to elixir, so i will give GenServer a try, all of my thoughts in the question was from detailed look at the documentations for that, so now that I have sort of an idea that I could be on the right path, i will go ahead and take a pass on that through a POC.

Also the AS does support 1 AT per client, but that AT has longer validity of around a day or something, to relieve / reduce chances of any dead lock situation, but having said that TeslaOAuth2ClientAuth looks great as well, will take a pass at it later.

Thanks again for helping out.

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

Latest on Elixir Forum

Elixir Forum

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews