Repository navigation
Exempt named Taskcluster Matrix bots from LDAP enforcement - #565
Conversation
|
Conceptually seems fine; I wonder if it'll run afoul of anything wrt how we require |
|
I'm very aware I might open a big rabbithole: but is there some way to turn that into a generalized solutions for other Mozilla Matrix bot users? We have a few other bots ( Would this list of email addresses be something we can, in theory, expand to other addresses? I don't expect a lot here, but we have a few other bots who at some point need to be able to "sign in" again. :/ |
|
Extra note: Some accounts currently have |
| const email = event.user.email.toLowerCase(); | ||
| const exemptEmails = | ||
| SERVICE_ACCOUNT_EXEMPTIONS[event.client.client_id] || []; | ||
| if (event.user.email_verified && exemptEmails.includes(email)) { |
There was a problem hiding this comment.
I have yet to see a case where event.user.email_verified has been false.
I did some investigation for bhearsum a while back, that's still in Slack (ref).
My take: if we've exempted an email we probably don't care if it's been verified or not.
There was a problem hiding this comment.
My take: if we've exempted an email we probably don't care if it's been verified or not.
My reasoning is mostly: it looks like we want to use these more as an API/username for a bot account, in which case if it can receive email is sort of not important. Other IdPs may rely on that, for granting an account.
Yeah, we can make it into something more general. Auth0 recently released some features which make this simpler.
Yeah, that would be fine. My preference would be to merge this PR first, then as a follow-up the rest of the bot accounts exempted afterwards. Would you be able to file a ticket with any additional details? One (minor) caveat is: any work we do here we'll need to port over to Okta.
Hmm... re: bare username+password: we can probably do that, but I'd prefer to use FxA. Weird handwavy stuff: it looks like we try not to use the built-in Auth0 database. I'm not sure why this is the case. That's just a thing I've noticed. There are now good reasons though, mainly: an even more complicated login screen. |
Totally fine by me! I just wanted to raise this point because I'm 100% sure this will come up again in the future. I have no problems pointing people to create an FxA and allow-listing the address here. :) This also isn't something that's coming up now, all the existing bots still run fine without being touched, but we all know that's gonna change in the future. Thanks for the feedback! :) |
|
I had a quick chat with @petemoore, and he's okay with this being deployed on Monday. |
See bug 2072995.