[ 
https://issues.apache.org/jira/browse/KNOX-1741?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Sandor Molnar updated KNOX-1741:
--------------------------------

+Apache Knox 3.0.0 release preparation+
   
We are about to cut the 3.0.0 release branch. master will move on to 3.1.0.
This issue is currently unresolved and is not automatically included in 3.0.0. 
Please choose one of the following:
# If this belongs in 3.0.0: once the branch is cut, cherry-pick your commit(s) 
onto the new v3.0.0 branch in addition to master. Leave Fix Version = 3.0.0 so 
we can track it.
# Do nothing: we will move this issue to the next release (3.1.0) as part of 
release cleanup.
   
If we don't hear back and see no cherry-pick, the issue will be re-targeted to 
3.1.0. Thanks!

> KnoxSSO to Support IDP Initiated Flow
> -------------------------------------
>
>                 Key: KNOX-1741
>                 URL: https://issues.apache.org/jira/browse/KNOX-1741
>             Project: Apache Knox
>          Issue Type: Improvement
>          Components: KnoxSSO
>            Reporter: Larry McCay
>            Priority: Major
>             Fix For: 3.0.0
>
>
> Currently, KnoxSSO is constrained to an SP Initiated Flow - meaning, the user 
> must attempt to access a participating application before s/he is redirected 
> to an IdP for authentication.
> This restriction has been problematic for some deployments that have multiple 
> tenants or realms since the participating application has only a single URL 
> to redirect to when authentication is required.
> This JIRA is an umbrella for a few tasks in order to enable the following:
> # A landing page that displays a portal of available Topologies and then 
> services/UIs within each. Need to determine which topologies to inclulde - 
> maybe only those protected by KnoxSSO - which will require some Admin API 
> calls. This will be similar to the Okta portal page with tiles for UIs and 
> Services.
> # KnoxSSO protection of the landing page to insure that the user is logged in
> # A login form that includes username, password and realm - or perhaps a top 
> level page that requires realm only. This can become the URL that 
> participating application redirect the user to when a new authentication is 
> required.
> # Clicking into a Service rather than a UI should result in a REST Client 
> Page where the KnoxSSO token will be presented and results returned in a 
> scrollable textarea or meaningful rendering of JSON in a tree or table.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to