mirror of
https://github.com/openharmony/useriam_user_auth_framework.git
synced 2026-08-25 09:39:33 -04:00
master
fix : upgrade rollback Created-by: hejiaogirl Commit-by: hejiaogirl Merged-by: openharmony_ci Description: ### 一、内容说明(相关的Issue) #https://gitcode.com/openharmony/useriam_user_auth_framework/issues/1356 ### 二、建议测试周期和提测地址 建议测试完成时间:xxxx.xx.xx 投产上线时间:xxxx.xx.xx 提测地址:CI环境/压测环境 测试账号: ### 三、变更内容 * 3.1 关联PR列表 * 3.2 数据库和部署说明 1. 常规更新 2. 重启unicorn 3. 重启sidekiq 4. 迁移任务:是否有迁移任务,没有写 "无" 5. rake脚本:`bundle exec xxx RAILS_ENV = production`;没有写 "无" * 3.4 其他技术优化内容(做了什么,变更了什么) - 重构了 xxxx 代码 - xxxx 算法优化 * 3.5 废弃通知(什么字段、方法弃用?) * 3.6 后向不兼容变更(是否有无法向后兼容的变更?) ### 四、研发自测点(自测哪些?冒烟用例全部自测?) 自测测试结论: ### 五、测试关注点(需要提醒QA重点关注的、可能会忽略的地方) 检查点: | 需求名称 | 是否影响xx公共模块 | 是否需要xx功能 | 需求升级是否依赖其他子产品 | |------|------------|----------|---------------| | xxx | 否 | 需要 | 不需要 | | | | | | 接口测试: 性能测试: 并发测试: 其他: See merge request: openharmony/useriam_user_auth_framework!2056
Unified User Authentication (userauth)
Introduction
As a basic component of the User Identity & Access Management (IAM) subsystem, Unified User Authentication (userauth) implements unified user authentication and provides biometric feature authentication APIs to third-party applications.
Figure 1 userauth architecture
The userauth APIs support user authentication of the target Authentication Trust Level (ATL). The target ATL is specified by the service. The target user ID can be specified by the service (system service or basic system application) or obtained from the system context (third-party application).
Directory Structure
//base/useriam/user_auth_framework
├── frameworks # Framework code
├── interfaces # Directory for storing external interfaces
│ └── innerkits # Header files exposed to the internal subsystems
├── sa_profile # Profile of the Service ability
├── services # Implementation of the Service ability
├── test # Directory for storing test code
├── utils # Directory for storing utility code
├── bundle.json # Component description file
└── userauth.gni # Build configuration
Usage
Available APIs
Table 1 APIs for unified user authentication
| API | Description |
|---|---|
| getAvailableStatus(authType : AuthType, authTrustLevel : AuthTrustLevel) : number; | Obtains the available authentication status. |
| auth(challenge: BigInt, authType : AuthType, authTrustLevel: AuthTrustLevel, callback: IUserAuthCallback): BigInt; | Performs user authentication. |
Usage Guidelines
- Vendors must implement the following in a Trusted Execution Environment (TEE):
- Authentication scheme: Determine the user authentication scheme based on the user credentials entered and the target ATL.
- Authentication result evaluation: Evaluate whether the authentication reaches the target ATL based on the authentication result returned by the executor.
- The APIs defined in the header file
user_auth/v1_0/IUserAuthInterface.idlin the drivers_interface repository must be implemented in a TEE, and the security of user authentication scheme and result evaluation must be ensured.
Repositories Involved
Description
Languages
C++
99.2%
C
0.5%
JavaScript
0.2%