argoproj / argoproj/argo-workflows
Expand SSO RBAC with additional claims from JWT
- Dominant language
- Go
- Stars
- 17k
- Forks
- 3.7k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 138
Description
# Summary
We have a multi-tenant app and the JWT stores tenants to which the user has access. It would be nice to write an auth expression that include other claims in the JWT so that we could enforce a tenant.
# Use Cases
On our current project.
---
**Message from the maintainers**:
Love this enhancement proposal? Give it a 👍. We prioritise the proposals with the most 👍.
Contributor guide
Research direction
No implementation file, test, or entry point is named in the issue. Start by locating the SSO/RBAC authorization-expression handling and the JWT claim path, then determine how tenant claims could be exposed and how tenant enforcement would be tested.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, kubernetes
- Domain
- authentication, authorization, backend
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100