Token导航 LogoToken导航TokenDH.com
效率敏感数据clawhub未标认证来源可访问clear审计提醒

canvas-lms-idp-auto-refreshcanvas lms idp 自动刷新

Agent Skill

canvas-lms-idp-auto-refresh 用于补充效率相关能力,适合在 OpenClaw 中需要让 Agent 承接效率相关任务时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

2,804

周安装

118

GitHub Stars

公开资料未说明

下载量

982
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:canvas-lms-idp-auto-refresh(canvas lms idp 自动刷新)
来源仓库:https://github.com/summers-tars/canvas-lms-idp-auto-refresh
安装命令:
openclaw skills install canvas-lms-idp-auto-refresh
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install canvas-lms-idp-auto-refresh

简介

使用 RSA 加密凭证通过机构 CAS/SAML IDP 登录自动刷新 Canvas LMS API 令牌并管理令牌生命周期。

SKILL.md

name
canvas-lms-idp-auto-refresh
description
Auto-refresh Canvas LMS API tokens via institutional IDP (CAS/SAML) login. Use when: (1) Canvas API returns 401 and you need to re-authenticate, (2) setting up automated token lifecycle for any Canvas LMS deployment behind an institutional SSO (especially Chinese universities using id.fudan.edu.cn style IDP), (3) user asks about "canvas token expired", "自动刷新token", "elearning login", "IDP登录". Handles RSA-encrypted password auth, SSO ticket exchange, token creation and old token cleanup.

Canvas LMS — IDP Auto Token Refresh

Automate Canvas API token refresh by replaying institutional IDP login (CAS/SAML) with RSA-encrypted credentials.

How It Works

Entry URL → CAS/IDP (lck + authChainCode) → RSA encrypt password → authExecute
  → loginToken (JWT) → authnEngine → SSO ticket → Canvas session → create API token
  → (optional) delete old tokens by purpose → output NEW_TOKEN=xxx

The script handles the full IDP chain: cookie juggling, JavaScript-redirect handoff, CSRF extraction, and Canvas API token CRUD.

Quick Start

1. Install Dependencies

cd scripts/
python3 -m venv .venv
.venv/bin/pip install -r requirements.txt

Dependencies: requests, beautifulsoup4, pycryptodome, python-dotenv.

2. Configure Credentials

Copy .env.example to .env and fill in:

cp scripts/.env.example scripts/.env

Required fields:

  • ELEARNING_USERNAME — student/staff ID
  • ELEARNING_PASSWORD — password

Optional (defaults to Fudan eLearning):

  • ELEARNING_ENTRY_URL — CAS entry point
  • ELEARNING_IDP_BASE_URL — IDP base URL
  • ELEARNING_ENTITY_ID — SP entity ID
  • ELEARNING_TOKEN_PURPOSE — label for created tokens (default: "OpenClaw Auto Refresh Token")
  • ELEARNING_CLEANUP_OLD_TOKENS — auto-delete old tokens with same purpose (default: false)

3. Run

# Full flow: login → create token → cleanup old tokens
cd scripts && .venv/bin/python elearning_login.py --cleanup-old-tokens

# Debug mode (verbose HTTP logs + save debug artifacts)
cd scripts && .venv/bin/python elearning_login.py --debug --cleanup-old-tokens

# Dry-run: only test up to public key fetch (no login)
cd scripts && .venv/bin/python elearning_login.py --dry-run --debug

On success, the script prints NEW_TOKEN=<token_value> to stdout.

4. Integrate with Token Lazy-Loading

For agents that call Canvas API, implement a lazy-refresh pattern:

  1. Read saved token from file
  2. Validate with GET /api/v1/users/self — check HTTP status only (don't read body)
  3. If 200 → use token
  4. If 401 → run refresh script, capture NEW_TOKEN=, save to file, retry
  5. If refresh also fails → alert user (password changed, CAPTCHA triggered, etc.)

Key rules:

  • Validate once per session, not on every API call
  • Only re-validate on explicit 401 responses
  • Don't log or expose raw token values
  • The refresh takes ~2-3 seconds, run silently

Security

  • .env contains credentials — never commit to git (.env is gitignored by default)
  • debug_output/ may contain session cookies and encrypted payloads — sanitize before sharing
  • The script uses PKCS1v1_5 RSA encryption for password transport (matching the IDP's JS frontend)
  • Tokens are created with a purpose label for lifecycle management
  • Old tokens with matching purpose can be auto-deleted to avoid accumulation

Known Limitations

LimitationImpactMitigation
CAPTCHA/rate-limitingScript cannot solve human verificationAlert user, manual intervention needed
MFA/2FARequires interactive flow not supported by requestsNot supported; alert user
IDP interface changesJSON field names or HTML structure may changeDebug output (--debug) captures raw responses for diagnosis
Public key format changesScript supports PEM, Base64-DER, modulus+exponentIf new format appears, extend parse_public_key_payload()

Troubleshooting

Run with --debug to save artifacts to debug_output/:

SymptomCheck
未能从入口响应中解析到 lckdebug_output/entry_response.html — look for context_CAS_...
queryAuthMethods 未找到 userAndPwddebug_output/query_auth_methods.json — check moduleCode field
未从 authExecute 提取到 loginTokendebug_output/auth_execute.json — check code/message
未拿到关键会话 CookieCheck auth_execute.json for errors, authn_engine_response.html for CAPTCHA
Token API returns 401/422debug_output/cookies.txt for _csrf_token / _normandy_session
Cleanup failsdebug_output/cleanup_summary.json for failed entries

Adapting to Other Institutions

The IDP flow is based on a common CAS/SAML pattern used by many Chinese universities. To adapt:

  1. Change URLs in .env: ELEARNING_ENTRY_URL, ELEARNING_IDP_BASE_URL, ELEARNING_ENTITY_ID
  2. Test with --dry-run first to verify lck/authChainCode extraction
  3. If IDP uses different auth methods: modify pick_auth_chain_code() in auth_session.py
  4. If password encryption differs: modify encrypt_password_rsa() and parse_public_key_payload()

Tested with: Fudan University (id.fudan.edu.cn → elearning.fudan.edu.cn).

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

94.13%
按下载量换算924

安全审计

VirusTotal

通过

ClawScan

可疑

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills