Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/api_key/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->

API Key token authentication sends a token in either a header or query parameter of each API request.

E.g., Headers: `X-StorageApi-Token:your_token`
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,13 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/basic/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->

Basic Authentication provides the [HTTP Basic Authentication](https://en.wikipedia.org/wiki/Basic_access_authentication)
method. It requires entering a username and password in the configuration and sends the encoded values in the
`Authorization` header.

### User Interface
### User interface

In the user interface, you simply select the `Basic Authorization` method and enter the username and password.

Expand Down Expand Up @@ -39,11 +41,11 @@ They are also prefixed by the hash `#` character, which means they are stored [e
If the API expects something else than a username and password in the `Authorization` header, or if it requires
a custom authorization header, use the [Default Headers option](/components/extractors/generic-extractor/configuration/api/#headers).

## Configuration Parameters
## Configuration parameters
This `basic` type of authentication has no configuration parameters. The login and password must be provided in the
[`config` section](/components/extractors/generic-extractor/configuration/config/) of the Generic Extractor configuration.

## Basic Configuration Example
## Basic configuration example
Assume you have an API which requires you to use the HTTP Basic authentication to send the login and password in
the `Authorization` header. Assume that your login is `JohnDo` and password is `secret`. The following
configuration solves the situation:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/bearer_token/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->

Bearer token authentication sends a token in the `Authorization` header of each API request.

This method is available through UI. You can select the `Bearer Token` method and fill in the token.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->

*To configure your first Generic Extractor, follow our [tutorial](/components/extractors/generic-extractor/tutorial/).*
*Use [Parameter Map](/components/extractors/generic-extractor/map/) to help you navigate among various
configuration options.*
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,13 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/login/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->


Use the Login authentication to send a one-time **login request** to obtain temporary credentials
for authentication of all the other API requests.

## User Interface
## User interface

Note that this configuration option is not yet covered. You can add the JSON configuration using the `Custom` auth method.

Expand Down Expand Up @@ -51,7 +53,7 @@ A sample Login authentication looks like this:
}
```

## Configuration Parameters
## Configuration parameters
The following configuration parameters are supported for the `login` type of authentication:

- `loginRequest` (required, object) — a [job-like](/components/extractors/generic-extractor/configuration/config/jobs/) object describing the login request; it has the following properties:
Expand All @@ -77,7 +79,7 @@ is called only once before all other requests. To call the login request before
## Examples
Below are several examples showing you how to use various login authentication related features in Generic Extractor.

### Configuration with Headers
### Configuration with headers
Let's say you have an API which requires every API call to be authorized with the `X-ApiToken` header. The value of that header (an API
token) is obtained by calling the `/login` endpoint with the headers `X-Login` and `X-Password`. The `/login` endpoint response looks
like this:
Expand Down Expand Up @@ -128,7 +130,7 @@ will contain the header:

See [example [EX079]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/079-login-auth-headers).

### Configuration with Headers and Text Response
### Configuration with headers and text response
Let's say you have an API like the above, but it returns the login response as a plain text:

a1b2c3d435f6
Expand Down Expand Up @@ -181,7 +183,7 @@ will contain the header:

See [example [EX128]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/128-login-auth-text).

### Configuration with Query Parameters
### Configuration with query parameters
Let's say you have an API which requires an [HTTP POST](https://en.wikipedia.org/wiki/POST_(HTTP)) request with `username` and
`password` to the endpoint `/login/form`.
On a successful login, it returns the following response:
Expand Down Expand Up @@ -244,7 +246,7 @@ so the second API call will be sent as:
See [example [EX080]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/080-login-auth-query).
Notice that the example uses completely different URL for the login request.

### Parameter Overriding
### Parameter overriding
The above examples show how to use query parameters and headers separately. However, they can be mixed freely; they can also be
mixed with parameters and headers entered elsewhere in the configuration. The following example shows how parameters from
different places are merged together:
Expand Down Expand Up @@ -405,7 +407,7 @@ This causes Generic Extractor to call the **login request** every hour.

See [example [EX082]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/082-login-auth-expires).

### Expiration from Response
### Expiration from response
In case the credentials provided by the **login request** have a time-limited validity, use the `expires` option.
If the validity of the credentials is returned in the response, modify the [first example](#configuration-with-headers) to this:

Expand Down Expand Up @@ -453,7 +455,7 @@ This assumes that the response of the **login request** looks like this:

See [example [EX083]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/083-login-auth-expires-date).

### Relative Expiration from Response
### Relative expiration from response
In case the API returns credentials validity in the **login request** and that validity is expressed in seconds,
use the `expires` option together with setting `relative` to `true`.
The result is the behavior of the [first example](#expiration-basic) but the value is taken
Expand Down Expand Up @@ -504,7 +506,7 @@ This assumes that the response of the **login request** looks like this:

See [example [EX084]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/084-login-auth-expires-seconds).

### Login Authentication with Functions
### Login authentication with functions
Suppose you have an API which requires you to send a username and password separated by a colon and
base64 encoded — for example, `JohnDoe:TopSecret` (base64 encoded to `Sm9obkRvZTpUb3BTZWNyZXQ=`) in the
`X-Authorization` header to an `/auth` endpoint. The login endpoint then returns a token
Expand Down Expand Up @@ -568,7 +570,7 @@ uses the `login` authorization method to send them to the special `/auth` endpoi

See [example [EX100]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/100-function-login-headers).

### Login Authentication with Login and API Request
### Login authentication with login and API request
Suppose you have an API similar to the one in the [previous example](#login-authentication-with-functions).
It requires you to send a username and password separated by a colon and
base64 encoded — for example, `JohnDoe:TopSecret` (base64 encoded to `Sm9obkRvZTpUb3BTZWNyZXQ=`) in the
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/oauth10/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->


**Note** that this configuration option is not yet supported and the test endpoint button will not work.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/oauth20-login/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->


**Note** that this configuration option is not yet supported and the test endpoint button will not work.

Expand Down Expand Up @@ -40,15 +42,15 @@ for authentication of all the other API requests. A sample OAuth Login authentic
}
```

## Configuration Parameters
## Configuration parameters
The configuration parameters are identical to the [Login](/components/extractors/generic-extractor/configuration/api/authentication/login/) method.
The difference, however, is in the [function context](/components/extractors/generic-extractor/functions/#oauth-20-login-authentication-context).
The **login request** is assumed to require the OAuth2 authorization and its response must be in JSON format (plaintext is not supported).

## Examples
The following examples demonstrate how to use OAuth with a basic login request and Google API in Generic Extractor.

### Basic Configuration
### Basic configuration
The following configuration shows how to set up an OAuth **login request**:

```json
Expand Down Expand Up @@ -131,7 +133,7 @@ and sent to other API requests (`/users`).

See [example [EX105]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/105-oauth2-login).

### Google API Configuration
### Google API configuration
The following example shows how to set up the OAuth authentication for Google APIs. The access token is refreshed with each API call.

#### Generate access tokens
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/oauth20/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->


OAuth 2.0 Authentication is one of [two OAuth methods](/components/extractors/generic-extractor/configuration/api/authentication/#oauth) and
is supported only for [components registered in the developer portal](/components/extractors/generic-extractor/publish/).
Expand Down Expand Up @@ -76,7 +78,7 @@ Note that the properties `appKey` and `#appSecret` must exist even if not used b
to empty strings. For more information about OAuth 2, see the [official documentation](https://oauth.net/2/)
or learn [more about Keboola-OAuth integration](/extend/common-interface/oauth).

## Configuration Parameters
## Configuration parameters
The following configuration parameters are supported for the `oauth20` authentication type:

- `format` (optional, string) — If the OAuth service provider response is JSON, use the only possible
Expand All @@ -92,7 +94,7 @@ are available in the [OAuth function context](/components/extractors/generic-ext
## Examples
The following two examples demonstrate the support for OAuth 2 in Generic Extractor.

### Bearer Authentication
### Bearer authentication
The most basic OAuth authentication method is with "Bearer Token". If you have an API which supports
this authentication method, the following configuration can be used:

Expand Down Expand Up @@ -144,7 +146,7 @@ the header `Authorization: Bearer SomeToken1234abcd567ef` using the

See [example [EX103]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/103-oauth2-bearer).

### HMAC Authentication
### HMAC authentication
If you have an API which requires an [HMAC](https://en.wikipedia.org/wiki/Hash-based_message_authentication_code)
signed token, generate the correct signature using [functions](/components/extractors/generic-extractor/functions).
The following example assumes you obtain the following response from the API upon authentication:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,15 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/oauth_cc/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->

oAuth 2.0 Client Credentials authentication performs the [oAuth 2.0 client_credentials flow](https://auth0.com/docs/get-started/authentication-and-authorization-flow/client-credentials-flow).

This method is available through the UI and is implemented via the [Login](/components/extractors/generic-extractor/configuration/api/authentication/login/) method.

![img.png](/components/extractors/generic-extractor/configuration/api/authentication/oauth_cc.png)

### Configuration Parameters
### Configuration parameters

- `Login Request type`
- `Basic Auth`: The client_id and client_secret are sent in the Authorization header as a Basic authorization, e.g. `Authorization: Basic base64(client_id:client_secret)`.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,15 @@ redirect_from:
- /extend/generic-extractor/configuration/api/authentication/query/
---

<!-- Reference-type page. Content not yet re-verified against keboola/generic-extractor; see PRDCT-676. -->

Query Authentication provides the simplest authentication method, in which
the credentials are sent in the [request URL](/components/extractors/generic-extractor/tutorial/rest#url).
This method is most often used with APIs that authenticate using API tokens and
signatures. Dynamic values of query parameters can be generated using
[user functions](/components/extractors/generic-extractor/functions/).

## User Interface
## User interface
In the user interface, you simply select the `Query` method and enter the key-value pairs of the query parameters.

![img.png](/components/extractors/generic-extractor/configuration/api/authentication/query.png)
Expand All @@ -36,12 +38,12 @@ A sample Query authentication configuration looks like this:
}
```

## Configuration Parameters
## Configuration parameters
The following configuration parameters are supported for the `query` type of authentication:

- `query` (required, object): An object whose properties represent key-value pairs of the URL query.

## Basic Configuration Example
## Basic configuration example
Let's say you have an API that requires an `api-token` parameter (with value 2267709) to be sent with
each request. The following authentication configuration does exactly that:

Expand All @@ -60,7 +62,7 @@ configuration remains organized.

See [example [EX077]](https://github.com/keboola/generic-extractor/tree/master/doc/examples/077-query-auth).

## Configuration With Encrypted Token Example
## Configuration with encrypted token example
Usually, you want the value used for authentication to be encrypted (the `api-token` parameter with the value 2267709 in our example), so you do not expose it to other users or store it in the configuration
versions history. The following authentication configuration, combined with the parameter defined in the [`config`](/components/extractors/generic-extractor/configuration/config/) section, does
that (the value with the prefix `#` is encrypted upon saving the configuration):
Expand Down
Loading
Loading