bcgov / bcgov/api-services-portal

ACL Only Flow

Open
#32 0 comments 0 reactions 0 assignees View on GitHub
automation Epic wontfix
Dominant language
TypeScript
Stars
27
Forks
8
Avg merge
1d 45m
Merged PRs (30d)
13

Description

A new flow (`kong-acl-only`) is a flow that allows for any authentication plugin to be used in conjunction with the Kong 'acl' plugin.

Includes defining a product environment with this flow, helping the api owner setup the appropriate plugins, and the developer experience requesting access to it.

Known use cases:
* A user-based login that uses Kong's ACL to protect access once authenticated. In this case, the API Provider can use the Consumer "Link Consumer to Namespace" so that they can then use the Consumer Management functionality to manage the ACL. Developers would contact the API Provider directly to request access, rather than using the Directory in the Portal.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are identified. First map how product environments, authentication and Kong ACL plugins, API-owner setup, and developer access requests are represented in the portal; the issue is done when the kong-acl-only flow supports the described user-login and access-request use case.

Written by the indexing model from the issue text.

Assessment

Domain
api, authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.