finos / FDC3

An open standard for the financial desktop.
https://fdc3.finos.org
Other
194 stars 116 forks source link

Firewalls #1063

Closed robmoffat closed 1 week ago

robmoffat commented 1 year ago

For one of our members, they would like to run apps from multiple different members. This can be problematic from a firewall perspective in a way that (say) Symphony bots is not.

Can we have a discussion about this in the Identity/Security workstream?

kriswest commented 1 year ago

Due to domain-based filtering? The actual issue you wish to discuss isn't that clear from this issue. From the description given I'd assume all that's needed is whitelisting of URLs for apps you wish to use. Presumably, the domains that need whitelisting can be extracted from app directory records.

If there are deeper issues, for example, due to a web application firewall that's interfering in some other way, then it would be helpful to have that described in the issue.

robmoffat commented 1 year ago

Hi, I was in a meeting and wanted to capture this. Yes, effectively the problem is domain-based filtering. The wider problem is bureaucracy surrounding domain based filtering rules.

kriswest commented 5 months ago

@robmoffat do you still want to discuss this? If so perhaps @Yannick-Malins can add it to an agenda

kriswest commented 1 week ago

Closed due to lack of activity. Reopen if there is still a discussion to have here that is relevant to the FDC3 Standard (rather than just general IT policy)