Allow Ory project introspection over API with pat
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Lĩnh vực
- api, authentication, authorization
Hướng nghiên cứu
Issue không nêu tên tệp, bài kiểm thử hoặc điểm vào nào. Hãy bắt đầu bằng việc xem xét dự án Ory Network và mô hình truy cập workspace, cùng với API được sử dụng để cấu hình dự án; công việc được xem là hoàn tất khi một backend có thể đọc cấu hình dự án của chính nó bằng token có phạm vi dự án mà không cần quyền truy cập workspace.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
No response
Describe your problem
We're using a single tenant deployment model, where each of our back-ends gets its own Ory project. These back-ends would ideally be able to introspect their own project configs, as to be able to get info about i.e. which OIDC/SAML providers are registered, since this can happen out of band of the back-end with the self-service functionality there. If we want to enable this as is, that would require them to each have full workspace access, which would be a serious escalation of privilege for any one back-end.
Describe your ideal solution
Allow read-only project access using an access token scoped to that project.
Workarounds or alternatives
Some kind of intermediate service that holds the wak and authenticates each back-end would be a workaround for this, but the overhead would be considerable.
Version
network
Additional Context
No response
- Ngôn ngữ chính
- Shell
- Star
- 96
- Fork
- 8
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ory/network
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseĐang mởbug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowĐang mởfeat
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordĐang mởbug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 30/100
-
feat
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
Issue tương tự
-
🎙️ task - fix(deployer): deploy --env prep runs deploy:dev where the repo declares deploy:prepĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
-
backlog bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
WLAN-Pi/wlanpi-profiler#306 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: backend good first issue priority: P3 - low size: S type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Mizithra/ActiveTerrain#31 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
obra/superpowers#2422 ·
Maintainer thường phản hồi trong vòng 6 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
ComplianceAsCode/content#15152 ·
Maintainer thường phản hồi trong vòng 3 ngày