ministryofjustice / operations-engineering

This repository is home to the Operations Engineering's tools and utilities for managing, monitoring, and optimising software development processes at the Ministry of Justice. β€’ This repository is defined and managed in Terraform
https://user-guide.operations-engineering.service.justice.gov.uk/
MIT License
12 stars 5 forks source link

πŸ“Ÿ Assess Impact on PagerDuty SSO #4769

Closed connormaglynn closed 4 days ago

connormaglynn commented 3 weeks ago

πŸ‘€ Purpose

βœ… Definition of Done

πŸ““ Notes

levgorbunov1 commented 6 days ago

Image

levgorbunov1 commented 6 days ago

Contacted drobertson@pagerduty.com to see if they manage whitelist for us?

levgorbunov1 commented 6 days ago

GitHub social connection in Auth0 links to DockerSSO OAuth application in GitHub, why? - Lazy reuse of origin OAuth application, used for DockerSSO, due to Auth0 restriction of only allowing 1 GitHub social connection.

levgorbunov1 commented 6 days ago

Image

levgorbunov1 commented 6 days ago

Waiting on PagerDuty to get back to us.

levgorbunov1 commented 4 days ago

Anyone with a business domain i.e. not a personal gmail, yahoo, hotmail etc. account can login via SSO. We are not restricting by domain.

levgorbunov1 commented 4 days ago

Image

levgorbunov1 commented 4 days ago

Creating ticket to patch this vulnerability

levgorbunov1 commented 4 days ago

Current system would be unaffected by Google Workspace decomissioning.