Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1525538 - [RFE] Introduce post-login page that notifies user when they are being redirect to a domain outside of their openshift cluster
[RFE] Introduce post-login page that notifies user when they are being redire...
Status: CLOSED CURRENTRELEASE
Product: OpenShift Container Platform
Classification: Red Hat
Component: RFE (Show other bugs)
unspecified
Unspecified Unspecified
urgent Severity urgent
: ---
: 3.9.0
Assigned To: Paul Weil
Xiaoli Tian
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-12-13 09:14 EST by Robert Bost
Modified: 2018-09-19 10:12 EDT (History)
11 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-07-17 15:27:43 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Github https://github.com/openshift/origin/pull/18489 None None None 2018-02-13 10:29 EST

  None (edit)
Description Robert Bost 2017-12-13 09:14:50 EST
There needs to be a prompt/webpage to user when they are being navigated to a external domain after successfully logging in. Please see bz1478744 for details on how this can be done.

1. Why exactly do you need this feature? (List the business requirements here)
OpenShift has come up in multiple customer's anti-phishing campaigns. OpenShift's login page enables phishing attacks via open redirects (https://cwe.mitre.org/data/definitions/601.html).
 
2. How would you like to achieve this? (List the functional requirements here)
A post-login page that is only shown when user is being redirect to a domain outside of their openshift cluster.
Comment 15 Simo Sorce 2018-02-07 09:21:51 EST
Yes, it would
Comment 17 Simo Sorce 2018-02-13 10:29:47 EST
This is a Request For Enhancement, therefore the target release will be determined by engineering.
If the customer needs the feature backported to a specific release a backport bug should be opened and justfied.

Currently slated for 3.9, PR merged here:
https://github.com/openshift/origin/pull/18489
Comment 19 Steve Speicher 2018-07-17 15:27:43 EDT
Open new bug if problems are found. This RFE is complete

Note You need to log in before you can comment on or make changes to this bug.