Allow Ory project introspection over API with pat
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Área
- api, authentication, authorization
Línea de trabajo
El issue no menciona archivos, pruebas ni puntos de entrada. Empieza revisando el proyecto Ory Network y el modelo de acceso a workspaces, así como la API utilizada para la configuración del proyecto; se considera terminado cuando un backend puede leer su propia configuración de proyecto con un token específico del proyecto sin acceso al workspace.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
No response
Describe your problem
We're using a single tenant deployment model, where each of our back-ends gets its own Ory project. These back-ends would ideally be able to introspect their own project configs, as to be able to get info about i.e. which OIDC/SAML providers are registered, since this can happen out of band of the back-end with the self-service functionality there. If we want to enable this as is, that would require them to each have full workspace access, which would be a serious escalation of privilege for any one back-end.
Describe your ideal solution
Allow read-only project access using an access token scoped to that project.
Workarounds or alternatives
Some kind of intermediate service that holds the wak and authenticates each back-end would be a workaround for this, but the overhead would be considerable.
Version
network
Additional Context
No response
- Lenguaje dominante
- Shell
- Estrellas
- 96
- Forks
- 8
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ory/network
-
feat
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowAbiertofeat
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
Todos los issues de ory/network
Issues similares
-
Bug: pane path not quotedAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 67/100
-
Does a subagent definition's `tools:` bypass the permission check? One default-permission cellAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
pearu/agent-sandbox#156 ·
Los mantenedores suelen responder en 1 día
-
area/documentation squad/marvin
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
rancher/stackstate-product-docs#443 ·
Los mantenedores suelen responder en 1 día
-
Request: Remove Sikka appAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
getumbrel/umbrel-apps#6142 ·
Los mantenedores suelen responder en 2 días
-
triage/confirmed
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
agentscope-ai/agentscope#3030 ·
Los mantenedores suelen responder en 1 día