edx-enterprise icon indicating copy to clipboard operation
edx-enterprise copied to clipboard

feat: per-user secured Algolia API keys [BB-8083]

Open 0x29a opened this issue 1 year ago • 6 comments

Description

Adds a new endpoint that generates a secured Algolia API key capable of retrieving only data that is associated with enterprises linked to a requesting user. This is useful when you want to isolate enterprise learners, so they can't modify underlying Algolia requests to fetch the whole index content.

Testing steps

See https://github.com/openedx/frontend-app-learner-portal-enterprise/pull/887

0x29a avatar Dec 06 '23 12:12 0x29a

Thanks for the pull request, @0x29a!

What's next?

Please work through the following steps to get your changes ready for engineering review:

:radio_button: Get product approval

If you haven't already, check this list to see if your contribution needs to go through the product review process.

  • If it does, you'll need to submit a product proposal for your contribution, and have it reviewed by the Product Working Group.
    • This process (including the steps you'll need to take) is documented here.
  • If it doesn't, simply proceed with the next step.

:radio_button: Provide context

To help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:

  • Dependencies

    This PR must be merged before / after / at the same time as ...

  • Blockers

    This PR is waiting for OEP-1234 to be accepted.

  • Timeline information

    This PR must be merged by XX date because ...

  • Partner information

    This is for a course on edx.org.

  • Supporting documentation
  • Relevant Open edX discussion forum threads

:radio_button: Get a green build

If one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green.

:radio_button: Let us know that your PR is ready for review:

Who will review my changes?

This repository is currently unmaintained.

To get help with finding a technical reviewer, tag the community contributions project manager for this PR in a comment and let them know that your changes are ready for review:

  1. On the right-hand side of the PR, find the Contributions project, click the caret in the top right corner to expand it, and check the "Primary PM" field for the name of your PM.
  2. Find their GitHub handle here.

Where can I find more information?

If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources:

When can I expect my changes to be merged?

Our goal is to get community contributions seen and reviewed as efficiently as possible.

However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:

  • The size and impact of the changes that it introduces
  • The need for product review
  • Maintenance status of the parent repository

:bulb: As a result it may take up to several weeks or months to complete a review and merge your PR.

openedx-webhooks avatar Dec 06 '23 12:12 openedx-webhooks

I've run the tests and added @0x29a to the triage group so that test will run automatically going forward.

e0d avatar Dec 14 '23 19:12 e0d

Clicked the wrong button :)

e0d avatar Dec 14 '23 19:12 e0d

@0x29a Looks like there are some failed tests, can you please have a look?

e0d avatar Dec 14 '23 19:12 e0d

Thank you for adding me to the triage group, @e0d. :slightly_smiling_face:

Looks like there are some failed tests, can you please have a look?

Yep, the newer version, to which I cherry-picked this change, doesn't import gettext anymore. I fixed this.

0x29a avatar Dec 15 '23 12:12 0x29a

Hi @openedx/2u-titans! If you're still reviewing pull requests, would you be able to please review / merge this for us? Thanks!

mphilbrick211 avatar Feb 21 '24 14:02 mphilbrick211