You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
It has come to our attention that the already existing following jars (existing in webapps/api directory of IAM accelerator) in the accelerator are not tend to be used for the CIBA push based authentication scenarios. This was identified during the discussion done in the mail thread [1].
At the time of this issue is created, no customer used the above jars. Hence, as discussed, the above jars will be removed from the product. The IS team also deprecated the repository related to the above jars and they are recommending to move to the newer push authentication implementation which is currently in progress and tracked via the mail [2].
We need to use the newer implementation when it is ready for OB CIBA scenarios as well. This issue is created to track it.
[1]: "Security issues reported in "identity-outbound-auth-push" repository"
[2]: "[Architecture] [IS/Asgardeo] Introducing push notification based authentication"
Suggested Labels:
Accelerator
Suggested Assignees:
Affected Product Version:
Accelerator 3
OS, DB, other environment details and versions:
Steps to reproduce:
Related Issues:
The text was updated successfully, but these errors were encountered:
All the fixes related to removing CIBA push authenticator from OB accelerator are now complete. Keeping this issue open to refer when the IS team finished implementing the new authenticator from their side so we can incorporate it with the CIBA implementation.
Description:
It has come to our attention that the already existing following jars (existing in
webapps/api
directory of IAM accelerator) in the accelerator are not tend to be used for the CIBA push based authentication scenarios. This was identified during the discussion done in the mail thread [1].At the time of this issue is created, no customer used the above jars. Hence, as discussed, the above jars will be removed from the product. The IS team also deprecated the repository related to the above jars and they are recommending to move to the newer push authentication implementation which is currently in progress and tracked via the mail [2].
We need to use the newer implementation when it is ready for OB CIBA scenarios as well. This issue is created to track it.
[1]: "Security issues reported in "identity-outbound-auth-push" repository"
[2]: "[Architecture] [IS/Asgardeo] Introducing push notification based authentication"
Suggested Labels:
Accelerator
Suggested Assignees:
Affected Product Version:
Accelerator 3
OS, DB, other environment details and versions:
Steps to reproduce:
Related Issues:
The text was updated successfully, but these errors were encountered: