Skip to content

Commit f70a821

Browse files
committed
Hard fork to AWS Okta Keyman
* AWS Okta Keyman v0.2.0 * Fix/improve software license documentation * Include license files * Update README.md as needed * Rename requirements.test.txt for better tab completion * Duo Auth support included * Multiple AWS role support included * Update from pep8 to pycodestyle * Minor style fixes * Prepare for distribution on PyPi
1 parent ba02715 commit f70a821

21 files changed

+302
-139
lines changed

.circleci/config.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,17 +18,17 @@ jobs:
1818
python -m venv venv || virtualenv venv
1919
. venv/bin/activate
2020
pip install -r requirements.txt
21-
pip install -r requirements.test.txt
21+
pip install -r test_requirements.txt
2222
- run:
2323
name: run tests
2424
command: |
2525
. venv/bin/activate
26-
nosetests -vv --with-coverage --cover-erase --cover-package=nd_okta_auth
26+
nosetests -vv --with-coverage --cover-erase --cover-package=aws_okta_keyman
2727
- run:
28-
name: pep8
28+
name: pycodestyle
2929
command: |
3030
. venv/bin/activate
31-
python setup.py pep8
31+
python setup.py pycodestyle
3232
- run:
3333
name: pyflakes
3434
command: |

.gitignore

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
dist
77
MANIFEST
88
README
9-
nd_okta_auth.egg-info
9+
aws_okta_keyman.egg-info
1010
.idea/
1111
build/
1212
htmlcov/

LICENSE.txt

Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
Apache License
2+
3+
Version 2.0, January 2004
4+
5+
http://www.apache.org/licenses/
6+
7+
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
8+
9+
1. Definitions.
10+
11+
"License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document.
12+
13+
"Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License.
14+
15+
"Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity.
16+
17+
"You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License.
18+
19+
"Source" form shall mean the preferred form for making modifications, including but not limited to software source code, documentation source, and configuration files.
20+
21+
"Object" form shall mean any form resulting from mechanical transformation or translation of a Source form, including but not limited to compiled object code, generated documentation, and conversions to other media types.
22+
23+
"Work" shall mean the work of authorship, whether in Source or Object form, made available under the License, as indicated by a copyright notice that is included in or attached to the work (an example is provided in the Appendix below).
24+
25+
"Derivative Works" shall mean any work, whether in Source or Object form, that is based on (or derived from) the Work and for which the editorial revisions, annotations, elaborations, or other modifications represent, as a whole, an original work of authorship. For the purposes of this License, Derivative Works shall not include works that remain separable from, or merely link (or bind by name) to the interfaces of, the Work and Derivative Works thereof.
26+
27+
"Contribution" shall mean any work of authorship, including the original version of the Work and any modifications or additions to that Work or Derivative Works thereof, that is intentionally submitted to Licensor for inclusion in the Work by the copyright owner or by an individual or Legal Entity authorized to submit on behalf of the copyright owner. For the purposes of this definition, "submitted" means any form of electronic, verbal, or written communication sent to the Licensor or its representatives, including but not limited to communication on electronic mailing lists, source code control systems, and issue tracking systems that are managed by, or on behalf of, the Licensor for the purpose of discussing and improving the Work, but excluding communication that is conspicuously marked or otherwise designated in writing by the copyright owner as "Not a Contribution."
28+
29+
"Contributor" shall mean Licensor and any individual or Legal Entity on behalf of whom a Contribution has been received by Licensor and subsequently incorporated within the Work.
30+
31+
2. Grant of Copyright License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form.
32+
33+
3. Grant of Patent License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable (except as stated in this section) patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work, where such license applies only to those patent claims licensable by such Contributor that are necessarily infringed by their Contribution(s) alone or by combination of their Contribution(s) with the Work to which such Contribution(s) was submitted. If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.
34+
35+
4. Redistribution. You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions:
36+
37+
You must give any other recipients of the Work or Derivative Works a copy of this License; and
38+
You must cause any modified files to carry prominent notices stating that You changed the files; and
39+
You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work, excluding those notices that do not pertain to any part of the Derivative Works; and
40+
If the Work includes a "NOTICE" text file as part of its distribution, then any Derivative Works that You distribute must include a readable copy of the attribution notices contained within such NOTICE file, excluding those notices that do not pertain to any part of the Derivative Works, in at least one of the following places: within a NOTICE text file distributed as part of the Derivative Works; within the Source form or documentation, if provided along with the Derivative Works; or, within a display generated by the Derivative Works, if and wherever such third-party notices normally appear. The contents of the NOTICE file are for informational purposes only and do not modify the License. You may add Your own attribution notices within Derivative Works that You distribute, alongside or as an addendum to the NOTICE text from the Work, provided that such additional attribution notices cannot be construed as modifying the License.
41+
42+
You may add Your own copyright statement to Your modifications and may provide additional or different license terms and conditions for use, reproduction, or distribution of Your modifications, or for any such Derivative Works as a whole, provided Your use, reproduction, and distribution of the Work otherwise complies with the conditions stated in this License.
43+
5. Submission of Contributions. Unless You explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work by You to the Licensor shall be under the terms and conditions of this License, without any additional terms or conditions. Notwithstanding the above, nothing herein shall supersede or modify the terms of any separate license agreement you may have executed with Licensor regarding such Contributions.
44+
45+
6. Trademarks. This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work and reproducing the content of the NOTICE file.
46+
47+
7. Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License.
48+
49+
8. Limitation of Liability. In no event and under no legal theory, whether in tort (including negligence), contract, or otherwise, unless required by applicable law (such as deliberate and grossly negligent acts) or agreed to in writing, shall any Contributor be liable to You for damages, including any direct, indirect, special, incidental, or consequential damages of any character arising as a result of this License or out of the use or inability to use the Work (including but not limited to damages for loss of goodwill, work stoppage, computer failure or malfunction, or any and all other commercial damages or losses), even if such Contributor has been advised of the possibility of such damages.
50+
51+
9. Accepting Warranty or Additional Liability. While redistributing the Work or Derivative Works thereof, You may choose to offer, and charge a fee for, acceptance of support, warranty, indemnity, or other liability obligations and/or rights consistent with this License. However, in accepting such obligations, You may act only on Your own behalf and on Your sole responsibility, not on behalf of any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against, such Contributor by reason of your accepting any such warranty or additional liability.
52+
53+
END OF TERMS AND CONDITIONS

LICENSE_MIT.txt

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
Copyright (c) 2015, Peter Gillard-Moss
2+
3+
All rights reserved.
4+
5+
Permission to use, copy, modify, and/or distribute this software for any
6+
purpose with or without fee is hereby granted, provided that the above
7+
copyright notice and this permission notice appear in all copies.
8+
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9+
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10+
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11+
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12+
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13+
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14+
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

MANIFEST.in

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
11
include README.md
2-
include requirements*
2+
include *.txt

README.md

Lines changed: 63 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
1-
[![CircleCI](https://circleci.com/gh/Nextdoor/nd_okta_auth.svg?style=svg&circle-token=7266b58fbbe52af8d01e72ce02d9fae6a7f4d1c6)](https://circleci.com/gh/Nextdoor/nd_okta_auth)
1+
[![Apache](https://img.shields.io/badge/license-MIT-blue.svg)](https://github.com/nathan-v/resque-state/blob/master/LICENSE.txt) [![PyPI version](https://badge.fury.io/py/aws_okta_auth.svg)](https://badge.fury.io/py/aws_okta_auth)
22

3-
# Nextdoor Okta Auth-er
3+
[![CircleCI](https://circleci.com/gh/nathan-v/aws_okta_keyman.svg?style=svg)](https://circleci.com/gh/nathan-v/aws_okta_keyman) [![CC GPA](https://codeclimate.com/github/nathan-v/aws_okta_auth/badges/gpa.svg)](https://codeclimate.com/github/nathan-v/aws_okta_auth) [![CC Issues](https://codeclimate.com/github/nathan-v/aws_okta_auth/badges/issue_count.svg)](https://codeclimate.com/github/nathan-v/aws_okta_auth) [![CC Coverage](https://codeclimate.com/github/nathan-v/aws_okta_auth/badges/coverage.svg)](https://codeclimate.com/github/nathan-v/aws_okta_auth)
4+
5+
# AWS Okta Keyman
46

57
This is a simple command-line tools for logging into Okta and generating
68
temporary Amazon AWS Credentials. This tool makes it easy and secure for your
@@ -16,61 +18,79 @@ tool has a few core features.
1618
## Optional MFA Authentication
1719

1820
If you organization requires MFA for the _[initial login into Okta][okta_mfa]_,
19-
we will automatically detect that requirement on a per-user basis and prompt
21+
we will automatically detect that requirement during authentication and prompt
2022
the user to complete the Multi Factor Authentication.
2123

2224
In paritcular, there is support for standard passcode based auth, as well as
23-
support for [Okta Verify with Push][okta_verify]. If both are available,
25+
support for [Okta Verify with Push][okta_verify] and Duo Auth. If both are available,
2426
Okta Verify with Push will be prioritized and a push notification is
2527
_automatically sent to the user_. If the user declines the validation, then
2628
optionally the Passcode can be entered in manually.
2729

30+
In the case of Duo Auth a web page is opened (served locally) for the user to
31+
interact with Duo and select their preferred authentication method. Once Duo is
32+
successful the user may close the browser or tab.
33+
34+
## Multiple AWS Roles
35+
36+
AWS Keyman supports multiple AWS roles when configued. The user is prompted to
37+
select the role they wish to use before the temporary keys are generated. An example
38+
of this is shown here:
39+
40+
17:10:21 (WARNING) Multiple AWS roles found; please select one
41+
[0] Role: arn:aws:iam::012345678910:role/admin_noiam
42+
[1] Role: arn:aws:iam::012345678910:role/readonly
43+
[2] Role: arn:aws:iam::012345678910:role/admin_full
44+
Select a role from above: 2
45+
17:10:22 (INFO) Assuming role: arn:aws:iam::012345678910:role/admin_full
46+
47+
2848
## Re-Up Mode .. Automatic Credential Re-Generation
2949

3050
Amazon IAM only supports Federated Login sessions that last up to *1 hour*. For
3151
developers, it can be painful to re-authenticate every hour during your work
3252
day. This is made much worse if your organization requires MFA on each login.
3353

34-
You may run the Okta Auth-er tool in "reup" mode to get around this. The tool
35-
will stay running in a daemon-like mode, and it will reach out regularly to
36-
Okta, generate a new SAML Assertion, and then generate updated Amazon AWS
54+
You may run the AWS Keyman in "reup" mode to get around this. The tool
55+
will continue to run in a sleep loop periodically reaching out to Okta,
56+
generating a new SAML Assertion, and then generating updated Amazon AWS
3757
credentials. This can run for as long as your Okta administrator has allowed
3858
your Login Session to be - often a full work day.
3959

4060
See the `--reup` commandline option for help here!
4161

4262
# Usage
4363

44-
For detailed usage instructions, see the `--help` commandline argument. Basic
45-
instructions though:
64+
For detailed usage instructions, see the `--help` commandline argument.
4665

47-
$ nd_okta_auth -a <application id> -o <your org name> -u <your username>
48-
08:27:44 (INFO) Nextdoor Okta Auther v0.0.1
66+
Typical usage:
67+
68+
$ aws_okta_keyman -a <application id> -o <your org name> -u <your username>
69+
08:27:44 (INFO) AWS Keyman v0.2.0
4970
Password:
5071
08:27:48 (WARNING) Okta Verify Push being sent...
5172
08:27:48 (INFO) Waiting for Okta Verification...
5273
...
5374
08:28:09 (INFO) Waiting for Okta Verification...
54-
08:28:10 (INFO) Successfully authed Matt Wise
75+
08:28:10 (INFO) Successfully authed Nathan V
5576
08:28:10 (INFO) Getting SAML Assertion from foobar
5677
08:28:11 (INFO) Found credentials in shared credentials file: ~/.aws/credentials
57-
08:28:11 (INFO) Wrote profile "default" to /Users/diranged/.aws/credentials
78+
08:28:11 (INFO) Wrote profile "default" to /Users/nathan-v/.aws/credentials
5879
08:28:11 (INFO) Session expires at 2017-07-24 16:28:13+00:00
5980
$
6081

6182
## Okta Setup
6283
Before you can use this tool, your Okta administrator needs to set up
6384
[Amazon/Okta integration][okta_aws_guide] using SAML roles.
6485

65-
## Inspiration
66-
This code is heavily based on the previous work done by
67-
[ThoughtWorksInc][thoughtworksinc] on their [OktaAuth][oktaauth] and [AWS Role
68-
Credentials][aws_role_credentials] tools. We took their general purpose code
69-
and re-wrote them into a singularly focused tool that added some new features.
86+
## Background
87+
This is a hard fork of [nd_okta_auth][nd_okta_auth] by [Nextdoor.com, Inc.][nextdoorinc].
88+
I decided to move ahead this way as I wanted to be able to move quickly and add
89+
features independently of the existing implementation.
7090

71-
In particular, we found it clumsy to use two CLI tools together to do a single
72-
task. Additionally, the tools did not have support for [Okta Verify with
73-
Push][okta_verify].
91+
The original code is heavily based on the previous work done by
92+
[ThoughtWorksInc][thoughtworksinc] on their [OktaAuth][oktaauth] and [AWS Role
93+
Credentials][aws_role_credentials] tools.
7494

7595
# Developer Setup
7696

@@ -80,15 +100,36 @@ environment is quick and easy.
80100
$ virtualenv .venv
81101
$ source .venv/bin/activate
82102
$ pip install -r requirements.txt
103+
$ pip install -r test_requirements.txt
83104

84105
## Python Versions
85106

86107
Python 2.7.1+ and Python 3.5.0+ are supported
87108

88109
## Running Tests
89110

90-
$ nosetests -vv --with-coverage --cover-erase --cover-package=nd_okta_auth
111+
$ nosetests -vv --with-coverage --cover-erase --cover-package=aws_okta_keyman
112+
113+
## Code Style
114+
115+
This project uses `pycodestyle` and `pyflakes` to check for style errors. Please
116+
use these tools to check changes before submitting PRs.
117+
118+
## License
119+
120+
Copyright 2018 Nathan V
121+
122+
Copyright 2018 Nextdoor.com, Inc
123+
124+
Licensed under the Apache License, Version 2.0. See LICENSE.txt file for details.
125+
126+
Some code in `aws_okta_keyman/okta.py`, `aws_okta_keyman/aws.py`,
127+
`aws_okta_keyman/aws_saml.py`, and `aws_okta_keyman/test/aws_saml_test.py` is
128+
distributed under MIT license. See the source files for details. A copy of the
129+
license is in the LICENSE_MIT.txt file.
91130

131+
[nd_okta_auth]: https://github.com/Nextdoor/nd_okta_auth
132+
[nextdoorinc]: https://github.com/Nextdoor
92133
[oktaauth]: https://github.com/ThoughtWorksInc/oktaauth
93134
[aws_role_credentials]: https://github.com/ThoughtWorksInc/aws_role_credentials
94135
[thoughtworksinc]: https://github.com/ThoughtWorksInc

nd_okta_auth/__init__.py renamed to aws_okta_keyman/__init__.py

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,4 +10,5 @@
1010
# See the License for the specific language governing permissions and
1111
# limitations under the License.
1212
#
13-
# Copyright 2017 Nextdoor.com, Inc
13+
# Copyright 2018 Nextdoor.com, Inc
14+
# Copyright 2018 Nathan V

nd_okta_auth/aws.py renamed to aws_okta_keyman/aws.py

Lines changed: 20 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,22 @@
1-
'''
2-
aws
3-
^^^
4-
5-
Simple module for writing generating and writing out AWS Credentials into your
6-
~/.aws/credentials file with a supplied Saml assertion.
7-
8-
Credits: This code base was almost entirely stolen from
9-
https://github.com/ThoughtWorksInc/aws_role_credentials. It continues to be
10-
modified from the original code, but thanks a ton to the original writers at
11-
Thought Works Inc.
12-
'''
1+
# -*- coding: utf-8 -*-
2+
#
3+
# Credits: Portions of this code were copied/modified from
4+
# https://github.com/ThoughtWorksInc/aws_role_credentials
5+
#
6+
# Copyright (c) 2015, Peter Gillard-Moss
7+
# All rights reserved.
8+
9+
# Permission to use, copy, modify, and/or distribute this software for any
10+
# purpose with or without fee is hereby granted, provided that the above
11+
# copyright notice and this permission notice appear in all copies.
12+
13+
# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
14+
# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
15+
# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
16+
# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
17+
# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
18+
# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
19+
# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
1320

1421
from __future__ import unicode_literals
1522
from builtins import str
@@ -21,7 +28,7 @@
2128
import xml
2229

2330
import boto3
24-
from nd_okta_auth.aws_saml import SamlAssertion
31+
from aws_okta_keyman.aws_saml import SamlAssertion
2532

2633
log = logging.getLogger(__name__)
2734

File renamed without changes.

0 commit comments

Comments
 (0)