Skip to content

Latest commit

 

History

History
113 lines (71 loc) · 4.11 KB

File metadata and controls

113 lines (71 loc) · 4.11 KB

Setting up frontiers as a Github App on Localhost

You should already have a .env file that you created by copying from .env.SAMPLE.

Start by following the instructions in [docs/oauth.md] to obtain values for these variables and setting them in .env

  • GOOGLE_CLIENT_ID
  • GOOGLE_CLIENT_SECRET

These instructions will explain how to fill in the values for:

  • GITHUB_CLIENT_ID
  • GITHUB_CLIENT_SECRET
  • app_private_key

Obtaining GITHUB_CLIENT_ID and GITHUB_CLIENT_SECRET

Go to https://github.com/

Then, click your profile icon. Click "Settings". Then, Click "Developer Settings", on the bottom of the toolbar on the left.

Select "New Github App". Fill in an appropriate name, and write it down. You will need it later.

image

For the homepage url, fill in http://localhost:8080.

image

Under Identifying and authorizing users, click the button "Add Callback URL"; this should make it so that you see two spaces in which you can add a Callback URL.

Fill these in as follows:

  • First callback URL: http://localhost:8080/api/courses/link
  • Second callback URL: http://localhost:8080/login/oauth2/code/github

Click the checkbox for "Request user authorization (OAuth) during installation"

image

Scroll down to permissions, and under repository, set the following accesses:

  • Administration: Read and Write
  • Contents: Read and Write
  • Metadata: Read-only
  • Workflows: Read and Write

Under Organization, select the following permissions:

  • Administration: Read and Write

Then, scroll further and uncheck "Active" under "Webhooks" (localhost testing doesn't need webhook functionality)

image

Note about webhook security: While webhooks are disabled for localhost, in production environments you must set up a webhook secret for security. The application requires a WEBHOOK_SECRET environment variable that is at least 10 characters long. For localhost development, you can set this to any value of 10+ characters in your .env file:

WEBHOOK_SECRET=localhost_dev_secret_123

Then, scroll further and under "Where can this Github App be installed?" select "Any Account"

Click "Create".

Now, Select "Generate Client Secret". Copy this client secret to a safe location, you will use it in a few minutes. Copy the Client ID as well.

image

  • Copy the value for the client id into GITHUB_CLIENT_ID in .env
  • Copy the value for the client secret into GITHUB_CLIENT_SECRET in .env

Generating a value for app_private_key

Scroll down to "Private Keys" and select "Generate a Private Key"

image

Next, we will run a script that converts this private key into a dokku config:set ... command.

Copy the key from wherever it downloaded to the root of the frontiers project, i.e. the directory where you cloned the repo.

For example, if ~/Downloads is the directory where files are downloaded, then this command will copy all files ending in .private-key.pem to your current directory.

cp ~/Downloads/*.private-key.pem .

Note that you must not commit this private key to the Github Repo! The .gitignore should handle this, but be careful in any case.

Now run this script:

./keyconvert-localhost.sh
  • If there is only one file ending in private-key.pem in the current directory, it will be selected automatically. Otherwise, you'll be asked to choose one.

The script will then output a file called secrets.yaml

app:
  private:
    key: "-----BEGIN PRIVATE KEY-----
<Your Key>
-----END PRIVATE KEY-----
"

You should now be able to run the app using:

mvn spring-boot:run