Allow Ory project introspection over API with pat
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 35/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Ambito
- api, authentication, authorization
Direzione di ricerca
L’issue non indica file, test o punti di ingresso. Inizia esaminando il progetto Ory Network e il modello di accesso ai workspace, nonché l’API utilizzata per la configurazione del progetto; il lavoro è completato quando un backend può leggere la propria configurazione del progetto con un token con ambito limitato al progetto, senza accesso al workspace.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
No response
Describe your problem
We're using a single tenant deployment model, where each of our back-ends gets its own Ory project. These back-ends would ideally be able to introspect their own project configs, as to be able to get info about i.e. which OIDC/SAML providers are registered, since this can happen out of band of the back-end with the self-service functionality there. If we want to enable this as is, that would require them to each have full workspace access, which would be a serious escalation of privilege for any one back-end.
Describe your ideal solution
Allow read-only project access using an access token scoped to that project.
Workarounds or alternatives
Some kind of intermediate service that holds the wak and authenticates each back-end would be a workaround for this, but the overhead would be considerable.
Version
network
Additional Context
No response
- Lingua principale
- Shell
- Stelle
- 96
- Fork
- 8
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ory/network
-
bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseApertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowApertafeat
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordApertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 30/100
-
feat
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
Issue simili
-
bot-found bug priority: P3
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
madenvel/KalinkaPlayer#179 ·
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
jbaruch/coding-policy#621 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
mattpocock/skills#1134 ·
-
area:build bug P3
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
uttrflow/uttrflow-swift#2506 ·
I maintainer di solito rispondono entro 1 giorno