There needs to be a prompt/webpage to user when they are being navigated to a external domain after successfully logging in. Please see bz1478744 for details on how this can be done. 1. Why exactly do you need this feature? (List the business requirements here) OpenShift has come up in multiple customer's anti-phishing campaigns. OpenShift's login page enables phishing attacks via open redirects (https://cwe.mitre.org/data/definitions/601.html). 2. How would you like to achieve this? (List the functional requirements here) A post-login page that is only shown when user is being redirect to a domain outside of their openshift cluster.
Yes, it would
This is a Request For Enhancement, therefore the target release will be determined by engineering. If the customer needs the feature backported to a specific release a backport bug should be opened and justfied. Currently slated for 3.9, PR merged here: https://github.com/openshift/origin/pull/18489
Open new bug if problems are found. This RFE is complete