Skip to content

Commit

Permalink
Hard fork to AWS Okta Keyman
Browse files Browse the repository at this point in the history
* AWS Okta Keyman v0.2.0
* Fix/improve software license documentation
* Include license files
* Update README.md as needed
* Rename requirements.test.txt for better tab completion
* Duo Auth support included
* Multiple AWS role support included
* Update from pep8 to pycodestyle
* Minor style fixes
* Prepare for distribution on PyPi
  • Loading branch information
nathan-v committed Mar 8, 2018
1 parent ba02715 commit f70a821
Show file tree
Hide file tree
Showing 21 changed files with 302 additions and 139 deletions.
8 changes: 4 additions & 4 deletions .circleci/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,17 +18,17 @@ jobs:
python -m venv venv || virtualenv venv
. venv/bin/activate
pip install -r requirements.txt
pip install -r requirements.test.txt
pip install -r test_requirements.txt
- run:
name: run tests
command: |
. venv/bin/activate
nosetests -vv --with-coverage --cover-erase --cover-package=nd_okta_auth
nosetests -vv --with-coverage --cover-erase --cover-package=aws_okta_keyman
- run:
name: pep8
name: pycodestyle
command: |
. venv/bin/activate
python setup.py pep8
python setup.py pycodestyle
- run:
name: pyflakes
command: |
Expand Down
2 changes: 1 addition & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
dist
MANIFEST
README
nd_okta_auth.egg-info
aws_okta_keyman.egg-info
.idea/
build/
htmlcov/
Expand Down
53 changes: 53 additions & 0 deletions LICENSE.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
Apache License

Version 2.0, January 2004

http://www.apache.org/licenses/

TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION

1. Definitions.

"License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document.

"Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License.

"Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity.

"You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License.

"Source" form shall mean the preferred form for making modifications, including but not limited to software source code, documentation source, and configuration files.

"Object" form shall mean any form resulting from mechanical transformation or translation of a Source form, including but not limited to compiled object code, generated documentation, and conversions to other media types.

"Work" shall mean the work of authorship, whether in Source or Object form, made available under the License, as indicated by a copyright notice that is included in or attached to the work (an example is provided in the Appendix below).

"Derivative Works" shall mean any work, whether in Source or Object form, that is based on (or derived from) the Work and for which the editorial revisions, annotations, elaborations, or other modifications represent, as a whole, an original work of authorship. For the purposes of this License, Derivative Works shall not include works that remain separable from, or merely link (or bind by name) to the interfaces of, the Work and Derivative Works thereof.

"Contribution" shall mean any work of authorship, including the original version of the Work and any modifications or additions to that Work or Derivative Works thereof, that is intentionally submitted to Licensor for inclusion in the Work by the copyright owner or by an individual or Legal Entity authorized to submit on behalf of the copyright owner. For the purposes of this definition, "submitted" means any form of electronic, verbal, or written communication sent to the Licensor or its representatives, including but not limited to communication on electronic mailing lists, source code control systems, and issue tracking systems that are managed by, or on behalf of, the Licensor for the purpose of discussing and improving the Work, but excluding communication that is conspicuously marked or otherwise designated in writing by the copyright owner as "Not a Contribution."

"Contributor" shall mean Licensor and any individual or Legal Entity on behalf of whom a Contribution has been received by Licensor and subsequently incorporated within the Work.

2. Grant of Copyright License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form.

3. Grant of Patent License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable (except as stated in this section) patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work, where such license applies only to those patent claims licensable by such Contributor that are necessarily infringed by their Contribution(s) alone or by combination of their Contribution(s) with the Work to which such Contribution(s) was submitted. If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.

4. Redistribution. You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions:

You must give any other recipients of the Work or Derivative Works a copy of this License; and
You must cause any modified files to carry prominent notices stating that You changed the files; and
You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work, excluding those notices that do not pertain to any part of the Derivative Works; and
If the Work includes a "NOTICE" text file as part of its distribution, then any Derivative Works that You distribute must include a readable copy of the attribution notices contained within such NOTICE file, excluding those notices that do not pertain to any part of the Derivative Works, in at least one of the following places: within a NOTICE text file distributed as part of the Derivative Works; within the Source form or documentation, if provided along with the Derivative Works; or, within a display generated by the Derivative Works, if and wherever such third-party notices normally appear. The contents of the NOTICE file are for informational purposes only and do not modify the License. You may add Your own attribution notices within Derivative Works that You distribute, alongside or as an addendum to the NOTICE text from the Work, provided that such additional attribution notices cannot be construed as modifying the License.

You may add Your own copyright statement to Your modifications and may provide additional or different license terms and conditions for use, reproduction, or distribution of Your modifications, or for any such Derivative Works as a whole, provided Your use, reproduction, and distribution of the Work otherwise complies with the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work by You to the Licensor shall be under the terms and conditions of this License, without any additional terms or conditions. Notwithstanding the above, nothing herein shall supersede or modify the terms of any separate license agreement you may have executed with Licensor regarding such Contributions.

6. Trademarks. This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work and reproducing the content of the NOTICE file.

7. Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License.

8. Limitation of Liability. In no event and under no legal theory, whether in tort (including negligence), contract, or otherwise, unless required by applicable law (such as deliberate and grossly negligent acts) or agreed to in writing, shall any Contributor be liable to You for damages, including any direct, indirect, special, incidental, or consequential damages of any character arising as a result of this License or out of the use or inability to use the Work (including but not limited to damages for loss of goodwill, work stoppage, computer failure or malfunction, or any and all other commercial damages or losses), even if such Contributor has been advised of the possibility of such damages.

9. Accepting Warranty or Additional Liability. While redistributing the Work or Derivative Works thereof, You may choose to offer, and charge a fee for, acceptance of support, warranty, indemnity, or other liability obligations and/or rights consistent with this License. However, in accepting such obligations, You may act only on Your own behalf and on Your sole responsibility, not on behalf of any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against, such Contributor by reason of your accepting any such warranty or additional liability.

END OF TERMS AND CONDITIONS
14 changes: 14 additions & 0 deletions LICENSE_MIT.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
Copyright (c) 2015, Peter Gillard-Moss

All rights reserved.

Permission to use, copy, modify, and/or distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies.
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
2 changes: 1 addition & 1 deletion MANIFEST.in
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
include README.md
include requirements*
include *.txt
85 changes: 63 additions & 22 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
[![CircleCI](https://circleci.com/gh/Nextdoor/nd_okta_auth.svg?style=svg&circle-token=7266b58fbbe52af8d01e72ce02d9fae6a7f4d1c6)](https://circleci.com/gh/Nextdoor/nd_okta_auth)
[![Apache](https://img.shields.io/badge/license-MIT-blue.svg)](https://github.com/nathan-v/resque-state/blob/master/LICENSE.txt) [![PyPI version](https://badge.fury.io/py/aws_okta_auth.svg)](https://badge.fury.io/py/aws_okta_auth)

# Nextdoor Okta Auth-er
[![CircleCI](https://circleci.com/gh/nathan-v/aws_okta_keyman.svg?style=svg)](https://circleci.com/gh/nathan-v/aws_okta_keyman) [![CC GPA](https://codeclimate.com/github/nathan-v/aws_okta_auth/badges/gpa.svg)](https://codeclimate.com/github/nathan-v/aws_okta_auth) [![CC Issues](https://codeclimate.com/github/nathan-v/aws_okta_auth/badges/issue_count.svg)](https://codeclimate.com/github/nathan-v/aws_okta_auth) [![CC Coverage](https://codeclimate.com/github/nathan-v/aws_okta_auth/badges/coverage.svg)](https://codeclimate.com/github/nathan-v/aws_okta_auth)

# AWS Okta Keyman

This is a simple command-line tools for logging into Okta and generating
temporary Amazon AWS Credentials. This tool makes it easy and secure for your
Expand All @@ -16,61 +18,79 @@ tool has a few core features.
## Optional MFA Authentication

If you organization requires MFA for the _[initial login into Okta][okta_mfa]_,
we will automatically detect that requirement on a per-user basis and prompt
we will automatically detect that requirement during authentication and prompt
the user to complete the Multi Factor Authentication.

In paritcular, there is support for standard passcode based auth, as well as
support for [Okta Verify with Push][okta_verify]. If both are available,
support for [Okta Verify with Push][okta_verify] and Duo Auth. If both are available,
Okta Verify with Push will be prioritized and a push notification is
_automatically sent to the user_. If the user declines the validation, then
optionally the Passcode can be entered in manually.

In the case of Duo Auth a web page is opened (served locally) for the user to
interact with Duo and select their preferred authentication method. Once Duo is
successful the user may close the browser or tab.

## Multiple AWS Roles

AWS Keyman supports multiple AWS roles when configued. The user is prompted to
select the role they wish to use before the temporary keys are generated. An example
of this is shown here:

17:10:21 (WARNING) Multiple AWS roles found; please select one
[0] Role: arn:aws:iam::012345678910:role/admin_noiam
[1] Role: arn:aws:iam::012345678910:role/readonly
[2] Role: arn:aws:iam::012345678910:role/admin_full
Select a role from above: 2
17:10:22 (INFO) Assuming role: arn:aws:iam::012345678910:role/admin_full


## Re-Up Mode .. Automatic Credential Re-Generation

Amazon IAM only supports Federated Login sessions that last up to *1 hour*. For
developers, it can be painful to re-authenticate every hour during your work
day. This is made much worse if your organization requires MFA on each login.

You may run the Okta Auth-er tool in "reup" mode to get around this. The tool
will stay running in a daemon-like mode, and it will reach out regularly to
Okta, generate a new SAML Assertion, and then generate updated Amazon AWS
You may run the AWS Keyman in "reup" mode to get around this. The tool
will continue to run in a sleep loop periodically reaching out to Okta,
generating a new SAML Assertion, and then generating updated Amazon AWS
credentials. This can run for as long as your Okta administrator has allowed
your Login Session to be - often a full work day.

See the `--reup` commandline option for help here!

# Usage

For detailed usage instructions, see the `--help` commandline argument. Basic
instructions though:
For detailed usage instructions, see the `--help` commandline argument.

$ nd_okta_auth -a <application id> -o <your org name> -u <your username>
08:27:44 (INFO) Nextdoor Okta Auther v0.0.1
Typical usage:

$ aws_okta_keyman -a <application id> -o <your org name> -u <your username>
08:27:44 (INFO) AWS Keyman v0.2.0
Password:
08:27:48 (WARNING) Okta Verify Push being sent...
08:27:48 (INFO) Waiting for Okta Verification...
...
08:28:09 (INFO) Waiting for Okta Verification...
08:28:10 (INFO) Successfully authed Matt Wise
08:28:10 (INFO) Successfully authed Nathan V
08:28:10 (INFO) Getting SAML Assertion from foobar
08:28:11 (INFO) Found credentials in shared credentials file: ~/.aws/credentials
08:28:11 (INFO) Wrote profile "default" to /Users/diranged/.aws/credentials
08:28:11 (INFO) Wrote profile "default" to /Users/nathan-v/.aws/credentials
08:28:11 (INFO) Session expires at 2017-07-24 16:28:13+00:00
$

## Okta Setup
Before you can use this tool, your Okta administrator needs to set up
[Amazon/Okta integration][okta_aws_guide] using SAML roles.

## Inspiration
This code is heavily based on the previous work done by
[ThoughtWorksInc][thoughtworksinc] on their [OktaAuth][oktaauth] and [AWS Role
Credentials][aws_role_credentials] tools. We took their general purpose code
and re-wrote them into a singularly focused tool that added some new features.
## Background
This is a hard fork of [nd_okta_auth][nd_okta_auth] by [Nextdoor.com, Inc.][nextdoorinc].
I decided to move ahead this way as I wanted to be able to move quickly and add
features independently of the existing implementation.

In particular, we found it clumsy to use two CLI tools together to do a single
task. Additionally, the tools did not have support for [Okta Verify with
Push][okta_verify].
The original code is heavily based on the previous work done by
[ThoughtWorksInc][thoughtworksinc] on their [OktaAuth][oktaauth] and [AWS Role
Credentials][aws_role_credentials] tools.

# Developer Setup

Expand All @@ -80,15 +100,36 @@ environment is quick and easy.
$ virtualenv .venv
$ source .venv/bin/activate
$ pip install -r requirements.txt
$ pip install -r test_requirements.txt

## Python Versions

Python 2.7.1+ and Python 3.5.0+ are supported

## Running Tests

$ nosetests -vv --with-coverage --cover-erase --cover-package=nd_okta_auth
$ nosetests -vv --with-coverage --cover-erase --cover-package=aws_okta_keyman

## Code Style

This project uses `pycodestyle` and `pyflakes` to check for style errors. Please
use these tools to check changes before submitting PRs.

## License

Copyright 2018 Nathan V

Copyright 2018 Nextdoor.com, Inc

Licensed under the Apache License, Version 2.0. See LICENSE.txt file for details.

Some code in `aws_okta_keyman/okta.py`, `aws_okta_keyman/aws.py`,
`aws_okta_keyman/aws_saml.py`, and `aws_okta_keyman/test/aws_saml_test.py` is
distributed under MIT license. See the source files for details. A copy of the
license is in the LICENSE_MIT.txt file.

[nd_okta_auth]: https://github.com/Nextdoor/nd_okta_auth
[nextdoorinc]: https://github.com/Nextdoor
[oktaauth]: https://github.com/ThoughtWorksInc/oktaauth
[aws_role_credentials]: https://github.com/ThoughtWorksInc/aws_role_credentials
[thoughtworksinc]: https://github.com/ThoughtWorksInc
Expand Down
3 changes: 2 additions & 1 deletion nd_okta_auth/__init__.py → aws_okta_keyman/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -10,4 +10,5 @@
# See the License for the specific language governing permissions and
# limitations under the License.
#
# Copyright 2017 Nextdoor.com, Inc
# Copyright 2018 Nextdoor.com, Inc
# Copyright 2018 Nathan V
33 changes: 20 additions & 13 deletions nd_okta_auth/aws.py → aws_okta_keyman/aws.py
Original file line number Diff line number Diff line change
@@ -1,15 +1,22 @@
'''
aws
^^^
Simple module for writing generating and writing out AWS Credentials into your
~/.aws/credentials file with a supplied Saml assertion.
Credits: This code base was almost entirely stolen from
https://github.com/ThoughtWorksInc/aws_role_credentials. It continues to be
modified from the original code, but thanks a ton to the original writers at
Thought Works Inc.
'''
# -*- coding: utf-8 -*-
#
# Credits: Portions of this code were copied/modified from
# https://github.com/ThoughtWorksInc/aws_role_credentials
#
# Copyright (c) 2015, Peter Gillard-Moss
# All rights reserved.

# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
# copyright notice and this permission notice appear in all copies.

# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

from __future__ import unicode_literals
from builtins import str
Expand All @@ -21,7 +28,7 @@
import xml

import boto3
from nd_okta_auth.aws_saml import SamlAssertion
from aws_okta_keyman.aws_saml import SamlAssertion

log = logging.getLogger(__name__)

Expand Down
File renamed without changes.
Loading

0 comments on commit f70a821

Please sign in to comment.