Bug 1525538 - [RFE] Introduce post-login page that notifies user when they are being redirect to a domain outside of their openshift cluster
Summary: [RFE] Introduce post-login page that notifies user when they are being redire...
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: RFE
Version: unspecified
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 3.9.0
Assignee: Paul Weil
QA Contact: Xiaoli Tian
Depends On:
TreeView+ depends on / blocked
Reported: 2017-12-13 14:14 UTC by Robert Bost
Modified: 2018-09-19 14:12 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2018-07-17 19:27:43 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Github https://github.com/openshift origin pull 18489 0 None None None 2018-02-13 15:29:46 UTC

Description Robert Bost 2017-12-13 14:14:50 UTC
There needs to be a prompt/webpage to user when they are being navigated to a external domain after successfully logging in. Please see bz1478744 for details on how this can be done.

1. Why exactly do you need this feature? (List the business requirements here)
OpenShift has come up in multiple customer's anti-phishing campaigns. OpenShift's login page enables phishing attacks via open redirects (https://cwe.mitre.org/data/definitions/601.html).
2. How would you like to achieve this? (List the functional requirements here)
A post-login page that is only shown when user is being redirect to a domain outside of their openshift cluster.

Comment 15 Simo Sorce 2018-02-07 14:21:51 UTC
Yes, it would

Comment 17 Simo Sorce 2018-02-13 15:29:47 UTC
This is a Request For Enhancement, therefore the target release will be determined by engineering.
If the customer needs the feature backported to a specific release a backport bug should be opened and justfied.

Currently slated for 3.9, PR merged here:

Comment 19 Steve Speicher 2018-07-17 19:27:43 UTC
Open new bug if problems are found. This RFE is complete

Note You need to log in before you can comment on or make changes to this bug.