Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Need to use the latest push based authenticator of IS for CIBA scenarios in the accelerator #233

Open
Akila94 opened this issue Dec 16, 2024 · 2 comments

Comments

@Akila94
Copy link
Member

Akila94 commented Dec 16, 2024

Description:
It has come to our attention that the already existing following jars (existing in webapps/api directory of IAM accelerator) in the accelerator are not tend to be used for the CIBA push based authentication scenarios. This was identified during the discussion done in the mail thread [1].

  • org.wso2.carbon.identity.api.user.push.device.common-0.1.1.jar
  • org.wso2.carbon.identity.api.user.push.device.handler.v1-0.1.1.jar

At the time of this issue is created, no customer used the above jars. Hence, as discussed, the above jars will be removed from the product. The IS team also deprecated the repository related to the above jars and they are recommending to move to the newer push authentication implementation which is currently in progress and tracked via the mail [2].

We need to use the newer implementation when it is ready for OB CIBA scenarios as well. This issue is created to track it.

[1]: "Security issues reported in "identity-outbound-auth-push" repository"
[2]: "[Architecture] [IS/Asgardeo] Introducing push notification based authentication"

Suggested Labels:
Accelerator

Suggested Assignees:

Affected Product Version:
Accelerator 3

OS, DB, other environment details and versions:

Steps to reproduce:

Related Issues:

@Akila94
Copy link
Member Author

Akila94 commented Dec 17, 2024

As a part of this, the current CIBA implementation will be deprecated from the accelerator.

@Akila94
Copy link
Member Author

Akila94 commented Jan 3, 2025

All the fixes related to removing CIBA push authenticator from OB accelerator are now complete. Keeping this issue open to refer when the IS team finished implementing the new authenticator from their side so we can incorporate it with the CIBA implementation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant