Skip to content

RFD 103: Application Access Web UI Auth Flow#20138

Merged
ryanclark merged 5 commits intomasterfrom
rfd/0103-application-access-auth-flow
Jan 12, 2023
Merged

RFD 103: Application Access Web UI Auth Flow#20138
ryanclark merged 5 commits intomasterfrom
rfd/0103-application-access-auth-flow

Conversation

@ryanclark
Copy link
Copy Markdown
Member

This documents the changes to the application access auth flow.

These changes have been implemented in #17592 and gravitational/webapps#1278

@ryanclark ryanclark force-pushed the rfd/0103-application-access-auth-flow branch from abc9698 to 8f7fbe3 Compare January 12, 2023 17:57
@github-actions github-actions Bot added rfd Request for Discussion size/sm labels Jan 12, 2023
Copy link
Copy Markdown
Collaborator

@zmb3 zmb3 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for getting something written down.

Comment thread rfd/0103-application-access-auth-flow.md Outdated
Comment thread rfd/0103-application-access-auth-flow.md Outdated
Comment thread rfd/0103-application-access-auth-flow.md Outdated
Comment thread rfd/0103-application-access-auth-flow.md Outdated
Comment thread rfd/0103-application-access-auth-flow.md Outdated
Copy link
Copy Markdown
Contributor

@GavinFrazar GavinFrazar left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for making this! Only comment I have is this is for the Web UI w/ cookies only. For app access via mTLS we added an extra check that the client cert subject matches the user who created the session (but covering the mTLS scenario is I think out of scope of what this is documenting).

Comment thread rfd/0103-application-access-auth-flow.md Outdated
@ryanclark ryanclark force-pushed the rfd/0103-application-access-auth-flow branch from 2245a7f to 52a262a Compare January 12, 2023 20:29
@ryanclark ryanclark enabled auto-merge (squash) January 12, 2023 20:39
@ryanclark ryanclark force-pushed the rfd/0103-application-access-auth-flow branch from ac03c84 to 9c31522 Compare January 12, 2023 20:39
@ryanclark ryanclark changed the title RFD 103: Application Access Auth Flow RFD 103: Application Access Web UI Auth Flow Jan 12, 2023
@ryanclark ryanclark disabled auto-merge January 12, 2023 20:40
@ryanclark ryanclark enabled auto-merge (squash) January 12, 2023 20:41
@ryanclark ryanclark force-pushed the rfd/0103-application-access-auth-flow branch from 9c31522 to f090ad6 Compare January 12, 2023 21:58
@ryanclark ryanclark merged commit 12cdaed into master Jan 12, 2023
@r0mant r0mant deleted the rfd/0103-application-access-auth-flow branch February 24, 2023 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

rfd Request for Discussion size/sm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants