Skip to content

Conversation

@ChrisMacNaughton
Copy link
Member

In both validating token permissions as well as validating SAML and
OIDC group membership, asserted_groups should be used to ensure that
any group membership requirements (eg: MFA) are upheld correctly.

Closes #390

In both validating token permissions as well as validating SAML and
OIDC group membership, asserted_groups should be used to ensure that
any group membership requirements (eg: MFA) are upheld correctly.

Closes #390
@coveralls
Copy link

Coverage Status

Coverage remained the same at 87.297% when pulling 6837043 on bug/groups-vs-asserted-groups into dfb7ba5 on main.

@ChrisMacNaughton ChrisMacNaughton merged commit fa06d8a into main Feb 5, 2022
@ChrisMacNaughton ChrisMacNaughton deleted the bug/groups-vs-asserted-groups branch February 5, 2022 09:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

asserted_groups aren't correctly used to limit permissions to SSO apps

3 participants