bcgov / cas-cif

CleanBC Industry Fund project
Apache License 2.0
6 stars 2 forks source link

Map out CIF authorization #1405

Open LindsayMacfarlane opened 1 year ago

LindsayMacfarlane commented 1 year ago

Describe the task

We need to clearly identify and document who can have access and to what within the CIF app (e.g., operators, consultants, etc).

Acceptance Criteria

Additional context

pbastia commented 1 year ago

Decision needs to be made about authentication/authorization via BCeID: do we enforce Business bceid? Do we allow basic? Do we give people access to all applications within their organisation?

dleard commented 1 year ago

Does CIF auth need its own epic so we can scope things down into smaller tickets?

pbastia commented 1 year ago

Probably, we'll have multiple tickets related to external users permissions

suhafa commented 1 year ago

@dleard @pbastia the AC for this ticket is more research based, would either of you want to change it so it reflects some first steps for authorization from dev-end of things?

suhafa commented 1 year ago

It would be a better approach to create a user story map first, and then identify user roles/access accordingly. Blocking this ticket and added a ticket (#1540) to do the user story mapping work first.

pbastia commented 1 year ago

AC for this card need to be a bit more refined

nanyangpro commented 1 year ago

Low priority for now in terms of the implementation according to @suhafa during backlog refinement Apr 25.

This is solely a research ticket, @pbastia suggested identifying the workflows for external users to login, (maybe BCeID user management as well?).

Output of this ticket should be added before removing the Backlog Refinement tag.