Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

dhicks

Members
  • Posts

    8,084
  • Joined

  • Last visited

Reputation

14,552 Excellent

About dhicks

Personal Information

  • Location
    Knightsbridge
  • Homepage
    http://www.sansay.co.uk

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. I have secrets (REST API keys, etc, that you get from the iSAMS Control Panel) in a simple JSON file, loadable by a script: # Load the configuration file. config = json.loads(dataLib.readFile("config/config.json")) for requiredConfigParameter in requiredConfigParameters: if not requiredConfigParameter in config.keys(): print("Error - required value " + requiredConfigParameter + " not set in config.json.") sys.exit(1) Something like: { "iSAMSAPIDomain":"exampleschool.isams.cloud", "iSAMSRESTAPIID":"12345678-1234-1234-1234-123456789012", "iSAMSRESTAPISecret":"12345678-1234-1234-1234-123456789012", } Then a couple of functions to call the REST API: # Retrive the cached iSAMS REST API Access Token, or request a new one if needed. def authenticateWithiSAMSRESTAPI(): if os.path.exists("accessToken.txt"): access_token = dataLib.readFile("accessToken.txt").strip() else: print("Authenticating with iSAMSREST API...", flush=True) requestURL = "https://" + config["iSAMSAPIDomain"] + "/auth/connect/token" response = requests.post(requestURL, data={"client_id":config["iSAMSRESTAPIID"],"client_secret":config["iSAMSRESTAPISecret"],"grant_type":"client_credentials","scope":"restapi"}) if not response.status_code == 200: print("Error athenticating with the iSAMS API:") print("URL: " + requestURL) print("Error Code: " + str(response.status_code)) print("Data: " + str(response.content)) sys.exit(1) access_token = json.loads(response.content.decode("utf8"))["access_token"] dataLib.writeFile("accessToken.txt", access_token) return access_token iSAMSAccessToken = authenticateWithiSAMSRESTAPI() # A handy function to do a call to the iSAMS REST API. Uses the global "iSAMSAccessToken" value for authentication - if that access token fails (default expiration is after 1 hour), # it gets a fresh access token and tries again. Only does 2 tries to avoid getting stuck in a loop. def iSAMSRESTAPICall(theMethod, theEndpoint, theData): global iSAMSAccessToken tries = 0 while tries < 2: tries = tries + 1 print("Doing " + theMethod + " to " + theEndpoint + " with data:", flush=True) print(str(theData).encode("utf-8"), flush=True) requestURL = "https://" + config["iSAMSAPIDomain"] + theEndpoint requestHeaders = {"accept":"application/json","authorization":"Bearer " + iSAMSAccessToken, "content-type":"application/json"} if theMethod == "get": response = requests.get(requestURL, data=json.dumps(theData), headers=requestHeaders) elif theMethod == "put": response = requests.put(requestURL, data=json.dumps(theData), headers=requestHeaders) elif theMethod == "patch": response = requests.patch(requestURL, data=json.dumps(theData), headers=requestHeaders) else: print("iSAMSRESTAPICall: Unknown request method: " + theMethod) if response.status_code == 200: return response elif response.status_code == 401 and tries < 2: print("iSAMSRESTAPICall: iSAMS authentication access token expired - retrying.") os.remove("accessToken.txt") iSAMSAccessToken = authenticateWithiSAMSRESTAPI() else: return response Then you can do calls to the REST API: getResponse = iSAMSRESTAPICall("get", "/Main/api/students/" + SchoolId, {}) if getResponse.status_code == 200: pupilData = json.loads(getResponse.text)
  2. This is the kind of thing where AI assistance can work really well, both in explaining how-it-works to you and, if you have a suitible coding agent, writing the code for you. If I remember correctly, iSAMS uses an OpenAPI/Swagger REST API interface - you might have seen other services offer the same thing, where you get a handy documentation and live try-it-out box all in one. You are basically doing HTTP(S) calls to a given endpoint, with defined parameters - the Swagger UI willl let you try out values and show you the URL strings (and even examples in Javascript / Python / etc) as you type. You authenticate via OAuth - I can't remember setting up a REST API with iSAMS, I suspect it was a while ago and I probably had to do a log-in-with-Google step in the browser the first time.
  3. There's a couple of "photos for work" apps that allow you, as an admin, to define where photos taken get synced to. Instead of the user taking a photo and then manually sharing to a location (e.g. somewhere on Googel Drive, for which they need to be logged in with their Google account, etc), the app simply takes the photo and uploads it to a defined cloud / network share. This saves a bunch of messing around, you could have a school-owned mobile device with a big sticker on the back ("Photos Phone 1") with the phoos app set as a kiosk (so it only does photos), any photo taken gets uploaded to a cloud-based folder that staff (maybe pupils) can access.
  4. VeryPC have some rather snazzy laptop stands with integrated USB-C connected docking ports which might be worth looking at.
  5. If you are meeting organistational security standards, you don't generally allow anyone-with-the-link sharing of files / folders to Google Drive / OneDrive any more. We still allow sharing between specific, named users, so a user on our Google Workspace could share a spreadsheet with a named user at the NHS. I could see that becoming a bit tricky to manage at the NHS side as your would have to support direct sharing from all vendors, and I suspect there will be a user limit to how many shares one named user could have, at which point you're probably looking at creating a separate user per school to receive shares. Probably do-able, but I suspect an API endpoint that accepts submissions of data is going to be simpler (and cheaper) to manage at the NHS side.
  6. A simple, well-defined, stable API for schools to be able to submit data to. It could probably be as simple as a single endpoint that accepts a CSV file. Schools could write their own tools to compile and submit data or, more likely, the vendors of common data-processing tools (Salamander, Locker, etc) could support it. You could, of course, also provide a simple submition form for people to upload the CSV file manually if they wanted. As others have pointed out, integrating with Wonde (or Clever, etc) would be ideal for many schools, as it would just be another service to approve on their Wonde dashboard and then that would be done. I understand that, while free for schools, Wonde charges per-customer for data access, so this might take some negotiation / budget allocation to sort - it would probably be the simplest option for a lot of schools, but I can understand there might be difficulties sorting this out at the NHS end if it involves having to pay a third-party vendor.
  7. Not sure if this is a hardware or software question. If it's a simple question of what hardware do we provide, then in our case each group of pupils could use a Chromebook to play music from whatever source was appropriate. Software-wise, you could simply put a bunch of tracks in a shared folder (Google Drive / Classroom, OneDrive, etc) and have the pupils play them from there. I find that a rather clunky system for sound effects and so on if you want things to play exactly on cue, so I have a script that generates a one-page sound effects playback webpage, giving you a handy "play" button for each audio item. Licensing is, of course, a separate issue - ripping tracks from Youtube and storing them in a Google Drive folder and distributing to a class probably doesn't meet whatever licensing requirements you have in place. If you need general background music to fit certain scenes / moods / etc you could probably get an AI system to generate a selection for you that you then store. You could, of course, give each group of pupils a microphone and a looper / vocoder and have them beatbox their own background accompniment.
  8. I'm finding the same. I'm not sure quite how repeatable a pure AI assistant is, the approach I've gone for is to use the AI coding agent to write a script that does what you want, then it's repeatable for subsequent actions. Also cheaper as it doesn't use AI tokens each time, just the first time round. It's interesting watching the agent scan the filesystem and figure stuff out - it does stuff pretty much how I would, just way, way quicker.
  9. That would seem to be what the new Mac Minis are aimed at - local AI processing should be very do-able with a fast processor and 64GB of unified RAM. I did get a very rough price from their website of around £3,000, which might be pricey for an individual workstation but not bad for a central on-site device usable by multiple users. Mac Minis can also, seemingly, be clustered via their Thunderbolt ports, so around £10,000 might get you a 4-node, 256GB AI processing cluster. Not something I know much about or have any current experience in setting up, but I did notice specialised AI servers being sold for £40,000 a few months ago.
  10. Hmm - we have Summer 2024-era 8GB-of-RAM iMacs in our ICT suite, I wonder if it's worth trying to run a local model of some sort on those?
  11. If it's any help, I have a 2011-era iMac running ChromeOS, which of course has a Linux core. It does have problems with the wireless hardware, having no supported driver available for the wireless used in that device, I wonder if your disk problem might be similar - it might manage to get to the initial boot stage, but need some sort of "driver" to get any further. It might, possibly, be instructive to try installing ChromeOS Flex on it and (if that boots) see if that can give you any hints as to how hardware might work.
  12. So, a couple of days and around £20 in AI tokens has produced this: https://www.sansay.co.uk/magooify/demo/ A somewhat specialised application for a specific image editing workflow - useful (hopefully) for the person wanting to use it, but rather niche otherwise. That would seem to be a strength of AI coding tools - I can now make tools for a "market" of one / a few people, and it's affordable and do-able in a reasonable timeframe. Using Go as the implementation language seems to have worked well and has produced an application capable of running on most hardware and with minimal resources - the live version is running on a VM with 2GB of RAM and 80GB of disk space, and that's for the whole system including authenticating proxy server (Pangolin), code to mount cloud file systems and the OpenCode tool for development.
  13. I'm starting to lean slightly towards the opposite view - the education sector (probably similar to other specialised sectors) has some poor software options, some of which it should be quite easy to re-implement quite rapidly with a coding agent. That's still probably a job for a small team rather than individuals in schools, just to keep continuity of development and keep projects / products maintained. A separate company, maybe, or for the larger company / school authority a team of in-house developers.
  14. Good point. And, as with spreadsheets, it's great that end users have the tools to handle their data how they want, but it would be good to have some kind of (auditable) controls on access, correctness, etc. Also, I tend to find the issue with spreadsheets is that they're a bit too easy for people to create a new one, so you wind up with data duplicated in multiple places.
  15. We do seem to be heading quite nicely to a situation where the people who understand the business process part of things (secretaries, PAs, etc) now have a suitable tool (AI coding agents) to allow them to create solutions that fit their problems, we (the IT support end of things) need to figure out how to support and manage that process and, as you point out, try and maintain security, usability, maintainability, etc. Also, to keep a careful eye on the AI credit spend. Some of the cheaper models now available are a couple of orders of magnitude cheaper than the top-performance ones, and for the kind of things I'm guessing our staff (and pupils!) will be doing I suspect the cheaper models might be the better option. Has anyone tried their own on-site AI server yet? I keep seeing various projects to cram versions of the latest models onto the kinds of machines we might be able to afford to run locally, has anyone tried using one of these with a coding agent yet?
×
×
  • Create New...