OpenConext / OpenConext/OpenConext-dashboard

SSID changes

Open
#629 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

not ready
Dominant language
JavaScript
Stars
8
Forks
2
PR merge metrics
No merged PRs in 30d

Description

This issue is imported from pivotal - Originaly created at May 12, 2021 by Raoul Teeuwen

At the moment, implementation of SSID features in the IdP dashboard is incomplete. This has been discussed at https://wiki.surfnet.nl/display/coininfra/SSID%2C+SURFconext+IdP+dashboard%2C+Manage . To fix this (ideally incorporated during the 2021 UI/UX redesign):
  • Currently, IdPs can set a LoA for a connected SP. This only makes sense for institutions that have ordered SSID. To detect whether an IdP has ordered SSID, we can check whether the RA SP is connected to the IdP. Only if it is, we want to offer an IdP the option to set a LOA for an SP
  • The IdP should not be able to set a LOA for the SSID RA SP (only SURF personnel should change those LOAs)
  • When the user filters for services with SSID, show a text-box at the bottom of the result list with the text “The above list only includes services connected to SURFconext and are configured to use SSID for your institution. Maybe your institution also uses other MFA/2FA solutions and flows with services that are not listed here.”
  • To include the “MFA-on-the-IdP” option SURFconext offers:
    o We want to add a facet filter under “SURFsecureID enabled”, “MFA on IdP”
    o Adding that filter makes the box title, “SURFsecureID enabled”, wrong. So change the title to “MFA/2FA”. Also, prefix all current SSID-filters with “SSID ”. So “IDP - loa2” becomes “SSID IDP - loa2” etc. Btw: afaik, the right way of writing IdP is IdP, not IDP
    o The current pop-up I help says “SURFsecureID second factor authentication is required.” > change to “Filter on several multi-/2-factor options.”

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in the dashboard UI by locating the SSID filters, the IdP LOA controls, the SSID result-list message, and the existing “SURFsecureID enabled” help text. Review the linked SSID requirements and trace how connected services and RA SP access are determined. Done means the requested LOA restrictions, filters, labels, explanatory text, and MFA/2FA wording all appear correctly.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
frontend
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.