hackforla / hackforla/tdm-calculator

Dev: Determine the steps needed to integrate Okta Auth0 product with TDM by the City

Open
#3,294 9 comments 0 reactions 1 assignee Claimed by @arshiamasih View on GitHub
deck: stakeholder presentation feature: DevOps feature: security testing level: hard priority: MUST HAVE role: back-end role: DevOps role: front-end size: 8pt status: 2 weeks inactive time sensitive
Dominant language
JavaScript
Stars
68
Forks
47
Avg merge
3d 9h
Merged PRs (30d)
25

Description

### Overview
The city wants all of their applications to use a Federated Sign-On by integrating their Auth0 implementation into each of the public-facing city web applications.

### Details
Back in 2023, the city requested that we integrate TDM with Okta's Workforce Integration product, which was designed for companies to implement Single Sign On for internal company applications. The product is licensed on a flat fee per-user / per-month and not designed for public-facing web applications. We also studied the implementation and found that they had not purchased the product that allowed authentication of requests to a Web API server. The implementation attempt was then scrapped when ITA informed us that they were abandoning the Workforce product and would be switching to the Auth0 product "at some point in the future".

To keep progress on TDM moving, we continued to evolve the custom authentication and authorization system already implemented in TDM.

In Q1 of 2026, the city indicated that they wanted to proceed with integrating Auth0 with TDM to replace the Authentication (and maybe the Authorization?) features of TDM.

Since TDM is being turned over to the City for production support and ongoing maintenance in August of 2026, Hack for LA does not have the time or resources to perform such a large change to TDM, but we have volunteered to at least try to determine if integration is feasible, and, if so, identify at a top-level what changes would need to be made.

### Action Items
- [x] Get access to the TDM Dev Ops 1password vault.
- [x] Learn how to use the "Jacob Rodes" Google account to access the city intranet to get access to the available documentation.
- [x] Read through the documentation at the links listed below in the Resources section.
- [x] Read through the Auth0 documentation for Auth0:
- [x] https://auth0.com/docs/quickstart/backend/nodejs
- [x] https://auth0.com/docs/quickstart/spa/react
- [x] Create a developer account with Okta for the Auth0 project to allow you to create a sample application.
- [x] You will probably need to work through an example react app with web api server example from the Auth0 documentation to actually figure out what all the pieces are and how they work.
- [x] Prepare a list of questions for the city to determine if they have any react and web api server applications that actually use Auth0, and what resources they might have that can be leveraged to help with the TDM integration.
- [x] Determine if Auth0 can only support Authentication, or if it can also support role-based authorization.
- [ ] A cursory reading of the documentation indicated that users with an email/login using the lacity.org domain are supposed to use some sort of Active Directory authentication system instead. Figure out how this impacts the integration.
- [ ] Work with the city to get an Auth0 test environment set up for TDM, and get permissions needed to configure it.
- [x] You might want to start by setting up the Auth0 sample app as a test placeholder application to verify that the environment can support a react / web api application.
- [ ] Review with product and dev. Update if needed based on feedback
- [ ] Once finalized, add before and after images to the slide in the staging deck for this issue (see link under resources)
- [ ] Get Stakeholder sign-off via the stakeholder meeting slide deck.

### Resources/Instructions
The companion Product Management Issue is -#1502

LInks to documentation provided by Michelle Leung (some are only available on the city intranet, which you can access by first logging into the Jacob Rodes Google account mentioned above).

- Google SSO: https://sites.google.com/lacity.gov/identity/integrations/onboarding
- SDK Libraries - Auth0 Docs: https://auth0.com/docs/libraries <-- Response (public site)
- Angeleno
- https://sites.google.com/lacity.gov/inside-angeleno-account?pli=1 <<- Angeleno (city intranet site)
- https://sites.google.com/lacity.gov/inside-angeleno-account/onboarding/overview (city intranet site)
- Link where other depts integrated their Angeleno Apps to our Auth0 environment - for public facing sites: https://account.lacity.gov/partner-services (public URL)

#### Staging and Release decks
- [Staging Deck](https://docs.google.com/presentation/d/1crZ3IxqA4hAu3qzD7ns93Ieuqjwh6wyEtuX_46cP-fg/)
- ~[Staging slide, 3294](https://docs.google.com/presentation/d/1crZ3IxqA4hAu3qzD7ns93Ieuqjwh6wyEtuX_46cP-fg/edit?slide=id.g3eb8ff4ade6_75_0#slide=id.g3eb8ff4ade6_75_0)~
- Release Deck
- [2025-08-18 Release deck, slide 1, 3294](https://docs.google.com/presentation/d/16-zgcjRJ6zjrAeTPZatTKdOAhuyhhqiN6bPsCsp0Huc/edit?slide=id.g3f9afe33a9e_0_0#slide=id.g3f9afe33a9e_0_0)
- [2025-08-18 Release deck, slide 2, 3294](https://docs.google.com/presentation/d/16-zgcjRJ6zjrAeTPZatTKdOAhuyhhqiN6bPsCsp0Huc/edit?slide=id.g3f9afe33a9e_0_61#slide=id.g3f9afe33a9e_0_61)
- [2025-08-18 Release deck, slide 3, 3294](https://docs.google.com/presentation/d/16-zgcjRJ6zjrAeTPZatTKdOAhuyhhqiN6bPsCsp0Huc/edit?slide=id.g3f9afe33a9e_0_67#slide=id.g3f9afe33a9e_0_67)
- [2025-08-18 Release deck, slide 4, 3294](https://docs.google.com/presentation/d/16-zgcjRJ6zjrAeTPZatTKdOAhuyhhqiN6bPsCsp0Huc/edit?slide=id.g3f9afe33a9e_0_73#slide=id.g3f9afe33a9e_0_73)
- [2026-09-15 Release deck, 3294](https://docs.google.com/presentation/d/1lBLDKK_hpjf_eWEjoVGg1RRqsxEh7RYEnFYDyuzbppE/edit?slide=id.g3fb66ad0ca0_0_405#slide=id.g3fb66ad0ca0_0_405)
- [2026-09-29 Release deck, 3294](https://docs.google.com/presentation/d/1U4rlSI31Gwqk03ju5xGqX3zAgjxJ--9eyVAdqJH4m7c/edit?slide=id.g3fb7a8857aa_0_61#slide=id.g3fb7a8857aa_0_61)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.