Pages

Showing posts with label top. Show all posts
Showing posts with label top. Show all posts

Wednesday, March 11, 2015

Building applications on top of Google Apps


Editors Note: This post was written by Michael Cohn and Steve Ziegler from Cloud Sherpas, a software development and professional services company. SherpaTools™ for Google Apps extends Google Apps capabilities. We invited Cloud Sherpas to share their experiences building an application on top of Google Apps utilizing some of our APIs. Cloud Sherpas will also be participating in the Developer Sandbox at Google I/O this May where theyll be demoing their use of Google technologies and answering questions from attendees.

The Directory Manager module of SherpaTools allows administrators to easily manage User Profiles and Shared Contacts in the Google Apps directory. SherpaTools is built on Google App Engine (GAE) utilizing the Google Web Toolkit (GWT), and makes heavy use of the Google Apps Management and Application APIs to provide new administrator and end-user features.

Some customers have tens of thousands of member accounts in their domain. SherpaTools Directory Manager makes it easy to retrieve, edit, and manage user accounts. It also allows you to import or export data in bulk from a Google Docs spreadsheet. This post explains how Directory Manager works with Google Apps, and how we built it. 


Authentication to SherpaTools is achieved by using Google Apps as the OpenID identity provider.  If a user is already logged into Google Apps, they can access SherpaTools without ever providing SherpaTools their credentials.  This Single Sign-On experience greatly enhances user adoption and provides an added security benefit.  If the user is not already logged into Google Apps, they are routed to a Google login page.  With OpenID, SherpaTools never handles the users credentials.


Once logged in, SherpaTools securely requests authorization from Google Apps using 2-legged OAuth (2LO) to make API service calls on behalf of the user.  Since the app has both an end-user and administrator view, it first retrieves the logged in users information from Google Apps via a 2LO-authorized call to the UserService of the Provisioning API.  Depending on the information sent in the API response, the user is either presented with the administrator application or the end-user screen.

Two-legged OAuth (2LO) allows 3rd-party applications like SherpaTools to make authorized API calls to Google Apps on behalf of a user. Here is how we set up our Google Data API ContactsService that will be fetching User Profiles to use 2LO: 

ContactsService contactsService =
    new ContactsService(GlobalConstants.APPLICATION_NAME);
GoogleOAuthParameters parameters = new GoogleOAuthParameters();
parameters.setOAuthConsumerKey(GlobalConstants.CONSUMER_KEY);
parameters.setOAuthConsumerSecret(GlobalConstants.CONSUMER_SECRET);
OAuthHmacSha1Signer signer = new OAuthHmacSha1Signer();
try {
   contactsService.setOAuthCredentials(parameters, signer);
} catch (OAuthException e) {
   // not expected if secret is up-to-date
}
As long as our key/secret pair is correct and the Google Apps customer has entitled our OAuth key to have access to their Contacts API feed, Google authorizes SherpaTools to continue to make API calls.  There are two other settings that should be mentioned in configuring the service to work well on GAE.  First, since we are dealing with somewhat sensitive data, all calls to Google Apps are made over SSL.  To ensure this, we simply set the useSSL flag for the contacts service.  Next, the default request/response timeout on GAE for these API calls is only five seconds out of a possible ten.  Since we will be retrieving as much data as we can within that ten second window to reduce the total number of operations to complete the work, we raise our connection timeout up to just short of that maximum, 9500 milliseconds:
contactsService.useSsl();
contactsService.setConnectTimeout(9500);
Cloud Sherpas embraced a number of Google Web Toolkit best practices to ensure scalability of SherpaTools.  For example, once the app determines which screen the user should see, SherpaTools employs GWT CodeSplitting to optimize and reduce the amount of javascript that needs to be downloaded by the browser client.  The app also uses the GWT RPC framework designed according to the command pattern to transparently communicate with the server, and was architected using the model-view-presenter (MVP) design pattern to allow multiple developers to work on the app simultaneously.


After a Google Apps administrator logs into SherpaTools for the first time, the app caches some key information for better performance.  For example, to populate the User Profile and Shared Contacts lists, the app retrieves the IDs and names of all contacts using the User Profiles API and Shared Contacts API respectively, and writes this information to the data store and memcache.  And for domains with large data sets, SherpaTools uses task queues to break up operations into smaller chunks. 


Since we have to scale the export to handle the contact information of tens of thousands of contact entries, there is no way we can retrieve all of those entries in one request.  Retrieval of this set of information requires breaking the operation up into smaller sub-tasks.  Fortunately, both the GAE Task Queue API and the Google Datastore APIs make it easy to divide the retrieval into smaller chunks.  

GAE Task Queues enable background queueing of HTTP operations (GET, POST, etc.) to arbitrary URLs within our application.  Each of these queued operations are subject to the same restrictions of any other GAE HTTP operation request.  Of particular note is the aforementioned 10 second window to perform our remote service call and the overall 30 second window to complete the total work within a task request. Also, since the Task Queue works from the same set of URLs as are made available to the rest of our application, we need to make sure that there is no ability for unwanted external attempts to execute tasks.  We followed the recommended way of eliminating this possibility by restricting outside access to just our applications admins. 


This constraint restricts all urls starting with /task/ to only be accessible either from system calls such as from the Task Queue or by admins.  The NONE transport guarantee is also important to mention.  We initially attempted to encrypt our task calls using SSL with a transport guaranteed of CONFIDENTIAL, but, at the time we attempted this, execution ceased to function properly.  Since all of the traffic of all of these calls are strictly on Googles internal network we had no issue with making these calls without SSL.
Now that we have our tasks properly secured, we can create a method for sending our User Profiles fetch task request to the Task Queue: 
public void fetchUserProfilesPageTask(String spreadsheetTitle,
    String loggedInEmailAddress, String nextLink, String memcacheKey) {
  Queue queue = QueueFactory.getQueue(USER_PROFILES_QUEUE);
  TaskOptions options =
      TaskOptions.Builder.url("/task/"+USER_PROFILES_FETCH_URL);
  options.param("spreadsheetTitle", spreadsheetTitle);
  options.param("loggedInEmailAddress", loggedInEmailAddress);
  options.param("nextLink", nextLink);
  options.param("memcacheKey", memcacheKey);
  queue.add(options);
}
The url points to a Java HttpServlet that handles the tasks HTTP POST, parses the sent parameters, and calls a method to perform the work:
protected void doPost(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
    String loggedInEmailAddress = req.getParameter("loggedInEmailAddress");
    String spreadsheetTitle = req.getParameter("title");
    String nextLink = req.getParameter("nextLink");
    String memcacheKey = req.getParameter("memcacheKey");
    // do the work:
    fetchUserProfilesPage(spreadsheetTitle, loggedInEmailAddress, nextLink, memcacheKey);
}

Summary

This post explains how SherpaTools Directory Manager uses Two Legged OAuth for authentication, and GAE Task Queue API and the Google Datastore APIs to make it easy to divide large retrievals over long intervals into smaller chunks. Other long-running, divisible operations, can use this same approach to spread work across a string of tasks queued in the GAE Task Queue. We would love to hear what you think of this approach and if you have come up with your own solution for similar issues.


Next week we will discuss how we used the User Profile API to retrieve the data sets and the Document List Data API to populate a Google Spreadsheet.


Thanks to the Cloud Sherpas team for authoring this post. Check out SherpaTools at www.sherpatools.com

Read more »

Friday, February 27, 2015

Top 100 Tools For Learning

Top 100 Tools: http://www.c4lpt.co.uk/recommended/top100.html
Top 10 Favourite Tools: http://www.c4lpt.co.uk/recommended/index.html
Zaids Top 10 Tools: http://www.c4lpt.co.uk/recommended/zaidalsagoff.html
The Learning Toolbox: http://www.c4lpt.co.uk/recommended/toolbox.html
Summary (PDF): http://www.c4lpt.co.uk/downloads/top100tools.pdf

This TOP 100 list has been compiled from the TOP 10 FAVOURITE TOOLS lists of many (target +100) learning professionals (consultants, analysts, developers, practitioners, academics, etc) who responded to Jan Knights open invitation. This list (together with the collection of Top 10 Tools list) is proving to be a popular resource to find out about the wide range of tools that can be used in a learning context - whether it be for personal learning or for creating learning for others - and demonstrates that e-learning is much much more than online courses.
Jane Knight (Learning Guru) and her team (I assume) has started a wonderful initiative (Simply Yummy), which can open our mind to what kind of tools that we can use to facilitate learning and why the learning experts chose them. Although, the top 100 list is certainly interesting (to basically know what tools are available and their ranking), I personally find it more stimulating and interesting to explore what the individual learning experts such as Stephen Downes, Jay Cross, and Clive Shepherd have chosen as their top 10 learning tools and importantly their straight-to-the-point justifications and reasons (Why?) for their selections. Also, you are recommended to check out the Learning Toolbox, which offers recommendations and suggestions for tools to use for different learning activities (It could save you from a lot of time-wasting on trial-and-error).
Thanks to Janes brilliant initiative (and idea I assume) we can acquire some constructive feedback from learning experts on learning tools without requiring to invest any mega bucks. Now, that itself is simply a Yummy Idea (at least for us)! Not only that, if we want to participate with our top 10 learning tools list, we can by simply clicking here :)
Here is my top 15 learning tools list (including short Whys):
  1. Internet Explorer (IE)
    Yes, Firefox is ranked number one on the Top 100 list. I have tried using Firefox for a few months early 2007, but I suppose I have gotten too used to IE and its "Favorites" management. I simply find it difficult quitting IE. I suppose after all these years using IE as my main browser to the knowledge galaxy it is difficult to let go. Though, I have both of them running on my PC, so I suppose sooner or later I will join the Firefox bandwagon (when it conquers IE in my mind).
  2. Google Search
    Videos (including YouTube), Glossary, Scholar, Blogs, Groups, Anything underneath the sun (especially for general stuff), etc. Googling is part of our life today. I wish I had more time to visit the traditional library.
  3. Moodle
    An Awesome course management system! The more you use it, the more you love it. Who said that open source is of no quality? It is simply an excellent tool to facilitate online learning (wikis, blogs, forums, chat, Instant Messaging, quizzes, polls, journals, database, e-books, basic content management, WYSIWYG editor, Item analysis, etc).
  4. PowerPoint
    Although, some instructional designers might hate it, it is still the most widely used tool by educators to prepare their lecture/tutorial presentations (and also use as e-learning content). Why? It enables you to do amazing stuff without much effort or skills. Also, with plug-ins like Adobe Breeze and Articulate you are empowered to construct dynamic multimedia audio-based Flash-light presentations. The only sucker with this tool is that it is not free. Also, Apple dudes would probably argue that Apples presentation software is better (Since I have not tried it, I cannot comment).
  5. Word
    Although, we have online processors like Buzzword and GoogleDocs, I still prefer to do most of my writing using Microsoft Word. However, you never know in the future, as these online processors continue to evolve and the Internet becomes easier to access.
  6. Google Reader
    Manages my RSS collection online. Since I discovered this tool I have given up on PC-based RSS tools. Now I can access my RSS collection on any computer device. Yummy!
  7. Gmail
    Easy-to-use, storage galore, no folders, search, and NO annoying video-based advertisements, entertainment and news like Yahoo and MSN mail. We are there to read/write our e-mails, not view news and entertainment (Be more creative in creating revenue), which we can get elsewhere (Think speed and ease-of-use when it comes to e-mail). Sometimes, all-in-one frustrates! The only reason why Gmail is not ranked higher, is because I still use my office mail a lot.
  8. Wikipedia
    Simply a massive wonderful disruptively fast growing learning resource (encyclopaedia), which you can find articles on basically everything. I suppose Answers.com is also worth mentioning, but without Wikipedia it would hardly be any answers in it.
  9. del.icio.us
    Excellent social bookmarking site. Saves me time to find juicy stuff.
  10. Blogger
    I suppose there are better blogging tools around, but I am kind of new to using blogs, so I will have to go with this one until I get a bit wiser.
  11. Slideshare
    Can store my PowerPoint slides (and other formats) online easily. Also, it is a super site to visit to learn the art of crafting a presentation. When I first visited this resource, I realized I have a long way to go to create great presentation slides (with learning outcomes). In short, it is a wonderful place to explore and be inspired by amazing works of art that strike a point (impact and learning outcomes).
  12. Google Notebook
    This is really an excellent research tool enabling you to browse, clip, and organize information from across the web in a single online location thats accessible from any computer.
  13. Google News
    It enables you to search and browse more than 4,500 news sources updated continuously according to different countries and categories like Sports, Sci/Tech, World, etc. Besides checking the regular news sites, I use this tool regularly to keep myself updated with the latest developments around the world. The Global/Local (Glocal) News RSS!
  14. Vivisimo Search
    Automated clustering (into folders) of search results (sometimes it clusters unexpected folders, helping me explore other dimensions of the original search).
  15. FreeMind
    A free and simple-to-use mind mapping software. I suppose the commercial ones are better, but to me it provides sufficient features to create a simply mind map of whatever you want to mind map.

In short, learning tools that enable you to easily create, share, communicate, collaborate, discuss, analyze, evaluate, aggregate, synergize, and find stuff are juicy tools of today and the future :)

Read more »