equinor / equinor/template-fastapi-react
Update IaC to generate multiple app registrations
- Dominant language
- TypeScript
- Stars
- 103
- Forks
- 13
- PR merge metrics
- No merged PRs in 30d
Description
#### Describe Problem
Currently, we use the same app registration / client id for the API and the front-end.
Since these two are different clients with different concerns, it is recommended to havve separate app registrations for the different applications / clients.
Some issues that show up when using a single app registration:
- The API does not need reply urls or the OpenID Connect scopes
- The front-end is a public client (until #391 is implemented), but the API is a confidential client
- The API may need additioanl scopes / API-permissions to call different services, which are not intended to be called directly from the front end
#### Suggest Solution
Create different app registrations (via bicep) for the different components (and environments)
#### Additional Details
Contributor guide
Assessment
This issue has not been assessed yet.