Bug 1525538

Summary: [RFE] Introduce post-login page that notifies user when they are being redirect to a domain outside of their openshift cluster
Product: OpenShift Container Platform Reporter: Robert Bost <rbost>
Component: RFEAssignee: Paul Weil <pweil>
Status: CLOSED CURRENTRELEASE QA Contact: Xiaoli Tian <xtian>
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: aoh, aos-bugs, jokerman, mbarrett, mhernon, mjs, mkhan, mmccomas, rbost, ssorce, sspeiche
Target Milestone: ---   
Target Release: 3.9.0   
Hardware: Unspecified   
OS: Unspecified   
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-07-17 19:27:43 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Robert Bost 2017-12-13 14:14:50 UTC
There needs to be a prompt/webpage to user when they are being navigated to a external domain after successfully logging in. Please see bz1478744 for details on how this can be done.

1. Why exactly do you need this feature? (List the business requirements here)
OpenShift has come up in multiple customer's anti-phishing campaigns. OpenShift's login page enables phishing attacks via open redirects (https://cwe.mitre.org/data/definitions/601.html).
2. How would you like to achieve this? (List the functional requirements here)
A post-login page that is only shown when user is being redirect to a domain outside of their openshift cluster.

Comment 15 Simo Sorce 2018-02-07 14:21:51 UTC
Yes, it would

Comment 17 Simo Sorce 2018-02-13 15:29:47 UTC
This is a Request For Enhancement, therefore the target release will be determined by engineering.
If the customer needs the feature backported to a specific release a backport bug should be opened and justfied.

Currently slated for 3.9, PR merged here:

Comment 19 Steve Speicher 2018-07-17 19:27:43 UTC
Open new bug if problems are found. This RFE is complete