6 SimpleAttach
David Anderson edited this page 2024-03-31 16:07:04 -07:00

Auto-attach: simplified registration/download process

This document describes a streamlined process by which volunteers on Windows and Mac computers download BOINC and attach to projects or account managers.

The current download/attach process has two problems:

  • Too many clicks.
  • Much of the GUI is in the Manager.

The new process reduces clicks and shifts most of the GUI to the web. This lets us use things like OpenAuth and Recaptcha, and provides a more unified experience.

Note: this process only works for "vetted" projects and AMs, i.e. those that appear on the BOINC web site. Making it work for arbitrary projects would decrease security. It works only on Win and Mac.

Currently (31 Mar 2024) only 8 out of the 28 vetted BOINC projects are using Simple Attach. Details.

New download/attach process

Front page

If no user is logged in, the project or AM front page has a button linked to a "Join" page (signup.php).

Join page

The page has a create account form. Submission of the form goes to the Download page (download_software.php).

Download page

This page says something like:

  • To participate in X, your computer must have BOINC (and possibly VBox) installed.
  • If these are already installed, a link to a page with instructions for adding project via the Manager.
  • Possibly instructions for installing VBox
  • Buttons to download BOINC and possibly BOINC+VBox. These show the download size, platform name, and version, like the download page on the BOINC web site.

Manager

When the manager is first run, it "auto-attaches" to the account on the project or account manager. No user interaction with the Manager is needed.

User experience

In summary, the new-user process is:

  1. Visit project or account manager web site, click on "Join".
  2. Enter email/password, click OK
  3. Click Download
  4. Click on installer, choose defaults

Improvements:

  1. User doesn't leave the project web site (e.g. doesn't land on BOINC web site)
  2. User doesn't see the list of all projects.

What projects must do to use this feature

  • Have your project vetted if not already.
  • Run the script html/ops/get_versions.php to get the current client version list. You must re-run this script after new client releases; I'll email to boinc_projects about this.
  • Add to config.xml:
<project_id>N</project_id>

where N is the project's ID, as shown in https://boinc.berkeley.edu/project_list.php. If your project requires VirtualBox, add

<need_vbox/>

If your project can use VirtualBox but doesn't require it, use

<recommend_vbox/>

If neither of these is present, VBox-related info won't be shown.

  • Add a button linking to signup.php on your home page (index.php).

Implementation

When a user is shown the Download page, the server code creates a "login token" - a random string. It stores the token and the current time in the user DB record.

The client installer is downloaded indirectly via a script on the BOINC web server (concierge.php). This is passed the project ID, the login token, and the installer filename. It downloads the file, appending the project ID and login token to the filename.

When the BOINC installer is launched, it writes the installer filename to a file "login_token.txt" in the BOINC data directory.

When the client startup it, it looks for this file. If found, does a "lookup account token" RPC to the project, obtaining the user name and a weak authenticator. It attaches to the project using this authenticator.