hardik.handa

hardik.handa

Planning on integrating with a client which accepts Oauth2 client credential based Token. The token validity is 1 day for now ( must mention that the client is completely internal and has no access to internet ).
Now there are two approaches that I am seeing fit:

  1. Either call for oauth token as a plug before every call to that client, fetch the token ( Seems like an overkill to be doing before every call to that client.
  2. Fetch the client token once everyday or whenever a new node is getting spun up, and then store it somehow as a state and then fetch the token just internally from that state everytime we have to call that client, if we get 401 on any call from the client, we reset the state, so that it leads to fetching of the token again.

Now I am not sure, should we be using GenServer for this or should we use Memoize for this. Any help or suggestion is more than welcome.

Thanks

Showing Posts 1 to 2

tangui

tangui

Calling the authorization server (AS) every time is indeed not performant, and it might even lead to some problems:

  • if the AS discards the former access tokens (ATs), you might have an in-flight request hitting the target API with an already invalidated AT
  • otherwise you’ll flood the AS with new ATs to store, and you might hit some limits

GenServer is a good fit for this problem (compared with ETS) because, even though request go through GenServer sequentially, you’re assured that in case the AT is expired, the first request hitting the GenServer will trigger token renewal and the others will just wait without requesting new ATs as well. Although if you have a very high number of processes making API requests, you might hit a bottleneck compared with ETS.

Note that some ASes only support 1 AT per client. If you’ve a multinode deployment, that might be a problem.

If you’re using Tesla, you could even write a middleware dealing with detecting expired tokens, requesting a new one when receiving an invalid_token error code (from RFC6750 - 3.1. Error Codes) and replaying the unauthorized request.

If the AS you’re using requires a complex client authentication scheme, you can take a look at TeslaOAuth2ClientAuth that implement some.

hardik.handa

hardik.handa OP

Thanks that really helps to bring perspective.
As I am new to elixir, so i will give GenServer a try, all of my thoughts in the question was from detailed look at the documentations for that, so now that I have sort of an idea that I could be on the right path, i will go ahead and take a pass on that through a POC.

Also the AS does support 1 AT per client, but that AT has longer validity of around a day or something, to relieve / reduce chances of any dead lock situation, but having said that TeslaOAuth2ClientAuth looks great as well, will take a pass at it later.

Thanks again for helping out.

— All posts loaded —

Where Next? Top

Trending in Questions Top

stjefim
Hello! Suppose you are building workflow (order / task / payment) processing system with the following requirements: Each workflow con...
New
Blokh
Hey guys, I’ve got a huge CSV ( around 10 GB ) that needs to be processed hourly Do you guys have any suggestions what is the best prac...
New
kszambelanczyk
Hello! Could someone please give me a help/sample code, how to delete a file from s3 using waffle/waffle_ecto from Phoenix app. I creat...
New
Onor.io
I have what I’ve heard referred to as a “lookup table” in my database. This is a way of assigning codes to common values. One common lo...
New
jaybe78
Hello, I’m developing a online persistent chat system (what’s app) like using elixir/dynamodb/aws for a mobile app(flutter). The diffic...
New
Trolleger
What approach to take when sending live updates to “random” users Hi! I have a question, I have a little chat app, and when I create a DM...
New
matt-savvy
Anyone here using Honeybadger? My Honeybadger account is being overwhelmed with noise from some bots. Seeing a lot of Bandit.HTTPError...
New

Other Trending Topics Top

garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
wintermeyer
There are three potential reasons for members of this forum to have a look at https://vutuv.de You are tired or annoyed of LinkedIn. Yo...
New
webofbits
Aludel - LLM Evaluation Workbench Aludel is an embeddable Phoenix LiveView dashboard for evaluating and comparing LLM prompts across mult...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews