DeployBoard / DeployBoard/deployboard-python

Implement Okta allowed_groups and allowed_domains

Offen
#143 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement
Vorherrschende Sprache
Python
Sterne
10
Forks
1
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

**Is your feature request related to a problem? Please describe.**
We can support additional security around Okta auth by implementing `allowed_groups` and `allowed_domains`.
This would restrict who can even log into the application, although personally, I don't think there is any reason to deny anyone in your organization access to DeployBoard, but that's not my call to make about your org, so we'd like to support the option at least.

**Describe the solution you'd like**
After the Okta Oauth2 workflow, we retrieve the user's info and check if they are in any of the `allowed_groups` in the config.

We additionally would check the Okta domain the request is coming from to verify the domain matches the `allowed_domains` list. I kinda think this one is a bit redundant, since we require you to put the Okta client and secret in the config, so that should always match the domain associated with that client right? We're planning to support it anyway.

**Describe alternatives you've considered**
None

**Additional context**
None

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Start by tracing the Okta OAuth2 workflow through the user's info retrieval and configuration handling. Determine how allowed_groups and allowed_domains should be represented and checked after authentication; done means users outside the configured groups or domains cannot log in, while permitted users can proceed.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
authentication, backend
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.