As announced at https://community.allstarlink.org/t/request-for-comment-application-authentication/24979, the forthcoming App Authentication is in development to replace the legacy "WebTransceiver" authentication mode. The standard ASL002 has moved into the Accepted state and development is largely complete. Please note this is NOT removing app-based communications it is ONLY changing how they authenticate.
App developers and node owners please take note of the following information.
Standards Information
The complete implementation information can be found at ASL002 Application Authentication
Development API is Available
The API is available for development testing at https://api-dev.allstarlink.org. The new API system supports OpenAPI documentation syntax and can be found at https://api-dev.allstarlink.org/schema/#tag/appauth.
Additionally, test script to demonstrate the the AppAuth API can be retrieved from https://api-dev.allstarlink.org/examples/appauth_client.py.
Note that api-dev.allstarlink.org may be perioditically unworking or unavailable as the code is being tested. However we expect this to be up at least 90% of the time between now and go-live.
Tentative Schedule
The following TENTATIVE deployment and implementation schedule is under review pending final QA testing of the system:
-
December 5, 2026: AppAuth is considered deployed and begins the 366 day deprecation and removal schedule of the 'WebTransceiver auth' system.
-
June 3, 2027: App logins using "WebTransceiver auth" will no longer be supported:
- The page
webtransceiver.phpwill be removed fromallstarlink.org - The page
login.phpis subject to change and no longer support "scrapable" tokens - The legacy API
/api/v2/auth-wt-legacy.phpwill be removed fromallstarlink.org
Apps that have not updated by this date will no longer work for end users.
- The page
-
December 6, 2027: Legacy and transitional methods described as RV2, RV3, and RV4 in ASL002 will be removed for node-based client verification. Nodes that have not updated their
extensions.confwill no longer be able to authenticate app clients.
Remaining Tasks
The following remaining tasks are necessary to completed before the transition begins:
Complete QA testing of the API system and deploy to production
Complete packaging changes to update extensions.conf in ASL3 installations
Provide a script and/or directions for legacy ASL and HamVOIP users to update extensions.conf
Send a complete announcement to all users ~ 2 weeks prior to the "go live" date
Inability to complete the above by mid-November will push the timeline into January 2027.