Altinn / Altinn/app-lib-dotnet

Limit access to API endpoints when using Maskinporten clients as a ServiceOwner

Open
#923 4 comments 0 reactions 0 assignees View on GitHub
kind/feature-request status/triage
Dominant language
C#
Stars
8
Forks
27
Avg merge
1h 21m
Merged PRs (30d)
7

Description

### Description

As a ServiceOwner, we are in need of limiting the scope on a system level, i.e limit the access only to the API endpoints exposed for App(s) that the used Maskinporten client has been configured for.

Example:
System A has Maskinporten_client_A setup with policies that only allows access to APIs of specified Apps in Altinn
System B has Maskinporten_client_B setup with policies that only allows access to APIs of specified Apps in Altinn

When using Maskinporten_client_A, API access should be limited to Apps in Altinn as specified in policies
When using Maskinporten_client_B, API access should be limited to Apps in Altinn as specified in policies

If System A tries to Instantiate an App outside of the specified policies of the Maskinporten client, the request should be denied
If System B tries to Instantiate an App outside of the specified policies of the Maskinporten client, the request should be denied

The request adheres to the principles of Zero Trust, that we believe should be followed.

Currently, either client would allow access to all apps owned by the ServiceOwner.

When we, as a ServiceOwner, using a Maskinporten client to request access to use the Altinn Apps APIs, scope is verified against the policy file as [org]. In other words the organisation is authenticated, without any further scope limitations.

Currently the required (only) scopes are:
altinn:serviceowner/instances.read
altinn:serviceowner/instances.write

Current functionality is also described here: https://docs.altinn.studio/api/authentication/maskinporten/

### Additional Information

This request might relate to
https://github.com/Altinn/altinn-authentication/issues/500
https://github.com/Altinn/app-template-dotnet/issues/23

Contributor guide

Open the contributing guide

Research direction

Start by reading the current Maskinporten authentication documentation and the related issues in altinn-authentication#500 and app-template-dotnet#23. Define how policy scopes map to App API access, then verify that clients are denied when instantiating apps outside their configured policies while permitted access continues to work.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
api, authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.