feat: fetching of a secured Algolia key [BB-8083] - #1
Merged
Agrendalath merged 2 commits intoNov 21, 2023
Merged
Conversation
0x29a
force-pushed
the
0x29a/bb8083/per-user-algolia-key
branch
from
November 10, 2023 14:00
6943b36 to
477e8ed
Compare
CefBoud
approved these changes
Nov 15, 2023
Agrendalath
approved these changes
Nov 16, 2023
Agrendalath
left a comment
Member
There was a problem hiding this comment.
@0x29a, this is awesome!
👍
- I tested this: learners cannot modify their queries to retrieve catalogs from other organizations; the behavior of this MFE does not change as long as we have the
ALGOLIA_SEARCH_API_KEYset - I read through the code
- I checked for accessibility issues: n/a
- Includes documentation: n/a
- I made sure any change in configuration variables is reflected in the corresponding client's
configuration-securerepository: n/a
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds a fallback mechanism, so when the
ALGOLIA_SEARCH_API_KEYenvironment variable is not set, the key is fetched from the endpoint defined by theALGOLIA_SECURED_KEY_ENDPOINTenvironment variable. It expects this endpoint to return a JSON like:{ "key": "<ALGOLIA_SEARCH_API_KEY>" }This is intended, but not limited to, to be used with open-craft/edx-enterprise#11.
Testing steps
We're going to test this PR, open-craft/edx-enterprise#11 and open-craft/openedx-platform#602 at once by creating three courses and three enterprise customers, uploading them to Algolia through
enterprise-catalogand checking that learners are able to browse catalogs of their enterprises with the help of this MFE, but unable to access courses of enterprises they don't belong to.Prerequisites
You'll need an Algolia account. Create an application and
enterprise-catalogindex. Write down the application id, admin API key, and search API key somewhere.Installing Palm devstack
After that:
cd ../edx-platformENTERPRISE_ALGOLIA_SEARCH_API_KEY = '<YOUR_ALGOLIA_SEARCH_(NOT ADMIN)_API_KEY>'to the end oflms/envs/devstack.py.Installing edx-enterprise fork
Installing enterprise-catalog
After that:
enterprise_catalog/apps/catalog/constants.pyand add'source'to theCONTENT_PRODUCT_SOURCE_ALLOW_LISTset.enterprise_catalog/settings/devstack.py:make dev.provision.Installing frontend-app-learner-portal-enterprise
Leave this terminal open, do all the remaining steps in a separate one.
Creating test entities
ABC,XYZ, andPSYfor all fields, like here:Course Start DateandEnrollment Start Datefor each course here to01/01/2019.verifiedandauditcourse modes for each course here: http://localhost:18000/admin/course_modes/coursemode/Sourcename here: http://localhost:18381/admin/course_metadata/source/add/{ "content_type":[ "course", "courserun" ], "aggregation_key":[ "course:ABC+ABC", "courserun:ABC+ABC" ], "partner":"edx", "availability":[ "Current", "Starting Soon", "Upcoming" ], "status":"published" }ABCtoXYZandPSYfor each query.XXX,YYY,ZZZ. Change their slugs respectively. CheckEnable learner portalfor each.XXXshould be assigned to the query selectingABCcourse,YYY->XYZandZZZ->PSY.Indexing
Go to the
<DEVSTACK_WORKSPACE>and replaceDEFAULT_PRODUCT_SOURCE_SLUG = ''withDEFAULT_PRODUCT_SOURCE_SLUG = 'source'incourse_discovery/settings/base.py.Then, go to the
<DEVSTACK_WORKSPACE>/devstackdirectory run the following to pull the data from LMS to Course Discovery:export OPENEDX_RELEASE=palm.master make discovery-shell ./manage.py refresh_course_metadataThen:
./manage.py populate_default_product_source ./manage.py update_index --disable-change-limit exitNow we need to copy course queries and other enterprise-related data from LMS to
enterprise-catalog. Run the following:This will fail, but it'll create a
enterprise_catalog_workeruser here. Go here and assignenterprise_catalog_adminrole toenterprise_catalog_worker@example.com, don't forget to checkApplies to all contexts.Now, run this again:
After that you should see three of your course queries here.
Now, go to the
<DEVSTACK_WORKSPACE>/enterprise-catalogand run the following to fetch content metadata (courses and course runs) from Course Discovery:After that you should see
CourseandCourse Runobjects for each of your courses here. If you don't, then something went wrong. Also,Json metadatafor each course should contain a non-emptyadvertised_course_run_uuid.Now you can upload all courses to Algolia:
If everything go fine, you should see three courses in your
enterprise-catalogAlgolia index.Enrolling users
abc@example.com.XXXenterprise customer and clickManager Learners(example of the admin panel URL).abc@example.comuser to thecourse-v1:ABC+ABC+ABCcourse. SpecifyAudittrack andtestreason for manual enrollment.enterprise_workeruser will appear here. Assign theenterprise_catalog_adminrole to theenterprise_worker@example.comuser here (don't forget to checkApplies to all contexts) and try point 3 again.YYYenterprise customer andcourse-v1:XYZ+XYZ+XYZcourse, so we have a single learner present in two different enterprises.Testing frontend-app-learner-portal-enterprise
abc@example.com.http://localhost:8734.abc@example.com, you should be offered to choose an organization. ChooseXXX.ABCcourse here.YYY, you should see theXYZcourse.Now, open the browser dev tools and locate a query like this:
Edit and Resend(that's for Firefox).Bodyfield and clickSend:{ "requests": [ { "indexName": "enterprise-catalog", "params": "facetingAfterDistinct=true&facets=%5B%5D&highlightPostTag=%3C%2Fais-highlight-0000000000%3E&highlightPreTag=%3Cais-highlight-0000000000%3E&tagFilters=" } ] }ABCandXYZcourses, omitting thePSYcourse.Upstream PR
openedx#887