Commit Graph

  • 37884e7015 reran update.sh to get the codegen up to date Margo Crawford 2022-06-09 14:39:06 -07:00
  • 889348e999 WIP aggregated api for oidcclientsecretrequest Margo Crawford 2022-06-09 13:45:21 -07:00
  • 484c8f4bf3 Merge pull request #1183 from anjaltelang/main Ryan Richard 2022-06-08 15:14:31 -07:00
  • 221f174768 Update v0.18.0 blog post date Ryan Richard 2022-06-08 15:14:02 -07:00
  • 3ebf5ad4c3 Updated versions in docs for v0.18.0 release Pinny 2022-06-08 22:13:13 +00:00
  • ec533cd781 Skip some recently added integration tests when LDAP is unavailable v0.18.0 Ryan Richard 2022-06-08 12:57:00 -07:00
  • 1f505fc065 Update audience confusion section of proposal doc Ryan Richard 2022-06-08 11:36:50 -07:00
  • dd61ada540 Allow new warning messages about GCP plugin in TestGetPinnipedCategory Ryan Richard 2022-06-08 10:22:15 -07:00
  • 0b6b8b4fcd Merge branch 'dynamic_clients' into token_exchange_aud Ryan Richard 2022-06-08 09:58:38 -07:00
  • 77f37b5a57 run codegen Ryan Richard 2022-06-08 09:41:35 -07:00
  • 321abfc98d Merge branch 'dynamic_clients' into token_exchange_aud Ryan Richard 2022-06-08 09:03:29 -07:00
  • 97d17bbda8 Merge branch 'main' into dynamic_clients Ryan Richard 2022-06-08 09:03:06 -07:00
  • cc1163e326 Merge pull request #1179 from vmware-tanzu/auth_handler_form_post_csp Mo Khan 2022-06-08 08:47:56 -04:00
  • ea45e5dfef Disallow certain requested audience strings in token exchange Ryan Richard 2022-06-07 16:32:19 -07:00
  • 472ab229e7 Merge branch 'main' into auth_handler_form_post_csp Mo Khan 2022-06-07 18:26:52 -04:00
  • 2c7b52dce8 Merge pull request #1186 from vmware-tanzu/bump_deps Mo Khan 2022-06-07 18:25:12 -04:00
  • 2c048bcb4f Bump all deps to latest Ryan Richard 2022-06-07 08:49:32 -07:00
  • e78c7d4e0e update kube codegen versions and add 1.24 codegen Ryan Richard 2022-06-06 16:01:26 -07:00
  • 7751c0bf59 Bump project deps, including kube 0.23.6->0.24.1 and Go 1.18.1->1.18.3 Ryan Richard 2022-06-06 14:37:22 -07:00
  • 8170889aef Update CSP header expectations in TestSupervisorLogin_Browser int test Ryan Richard 2022-06-07 11:20:59 -07:00
  • 38bfdd6b70 Merge branch 'main' into auth_handler_form_post_csp Mo Khan 2022-06-07 11:42:09 -04:00
  • e5a96e353c Merge pull request #1185 from vmware-tanzu/oidc_client_crd Margo Crawford 2022-06-06 14:16:10 -07:00
  • 52bbbcf7e8 margo's suggestions Anjali Telang 2022-06-03 10:59:51 -04:00
  • a3ec15862d Run CodeQL on dynamic_clients branch Mo Khan 2022-06-06 16:41:38 -04:00
  • 98c45fefe9 Merge branch 'main' into auth_handler_form_post_csp Ryan Richard 2022-06-06 11:51:51 -07:00
  • d6442ed53d Merge pull request #1180 from vmware-tanzu/cli_flow_env_var Margo Crawford 2022-06-06 11:49:00 -07:00
  • 0dec2eee32 Add enum validation for scopes and grant types Margo Crawford 2022-06-06 10:15:25 -07:00
  • fd9d641b5c Add doc for PINNIPED_UPSTREAM_IDENTITY_PROVIDER_FLOW env var Ryan Richard 2022-06-06 09:47:50 -07:00
  • 326cc194e9 Merge branch 'main' into cli_flow_env_var Ryan Richard 2022-06-06 09:38:57 -07:00
  • 3cacb5b022 Fix typo in oidcclient spec and status descriptions Margo Crawford 2022-06-06 07:38:57 -07:00
  • ca3da0bc90 Fix some disallowed kubebuilder annotations, fix kube api discovery test Margo Crawford 2022-06-04 21:04:40 -07:00
  • cd47ba53c2 Add CRD for OIDCClient Margo Crawford 2022-06-03 16:22:15 -07:00
  • 2f6349c96d Merge pull request #1166 from anjaltelang/main anjalitelang 2022-06-02 17:27:14 -04:00
  • 225bbdd36b Merge branch 'main' into main anjalitelang 2022-06-02 17:25:43 -04:00
  • 30d09b2b7e Empty commit Ryan Richard 2022-06-02 13:10:34 -07:00
  • cb8685b942 Add e2e test for PINNIPED_UPSTREAM_IDENTITY_PROVIDER_FLOW env var Ryan Richard 2022-06-02 11:27:54 -07:00
  • 6e461821d6 Allow PINNIPED_UPSTREAM_IDENTITY_PROVIDER_FLOW env var to override flow Ryan Richard 2022-06-02 10:30:03 -07:00
  • b99c4773a2 Use CSP headers in auth handler response Ryan Richard 2022-06-02 09:23:34 -07:00
  • 212f00ebde Recommend a single approach to address all goals Monis Khan 2022-05-16 16:23:49 -04:00
  • 75a32ae243 Merge pull request #1145 from enj/enj/f/json_logs Mo Khan 2022-05-24 13:15:22 -04:00
  • 0674215ef3 Switch to go.uber.org/zap for JSON formatted logging Monis Khan 2022-04-15 22:43:53 -04:00
  • 03ccef03fe Merge pull request #1163 from vmware-tanzu/ldap-login-ui Ryan Richard 2022-05-24 10:19:34 -04:00
  • 438ab0a0e1 Merge branch 'main' into ldap-login-ui Ryan Richard 2022-05-20 08:40:34 -07:00
  • 39fd9ba270 Small refactors and comments for LDAP/AD UI Ryan Richard 2022-05-19 16:02:08 -07:00
  • cc985aa98a Roadmap updates for future Anjali Telang 2022-05-19 15:53:53 -04:00
  • 7388097de7 Merge pull request #1116 from vmware-tanzu/proposal-ldap-web-ui Ryan Richard 2022-05-16 16:22:17 -07:00
  • f008c081b3 Accept LDAP UI proposal Ryan Richard 2022-05-16 16:21:33 -07:00
  • 1092fc4a9e Add PR link to LDAP UI proposal Ryan Richard 2022-05-16 16:21:17 -07:00
  • dc6874e9cd Move remaining open q's to answered q's Ryan Richard 2022-05-16 16:20:42 -07:00
  • 0f2a984308 Merge branch 'main' into ldap-login-ui Ryan Richard 2022-05-11 11:32:15 -07:00
  • 4101a55001 Update docs for new LDAP/AD browser-based login flow Ryan Richard 2022-05-11 11:19:08 -07:00
  • aa732a41fb Add LDAP browser flow login failure tests to supervisor_login_test.go Ryan Richard 2022-05-10 16:22:07 -07:00
  • 0b106c245e Add LDAP browser flow login test to supervisor_login_test.go Ryan Richard 2022-05-10 12:54:40 -07:00
  • ab302cf2b7 Add AD via browser login e2e test and refactor e2e tests to share code Ryan Richard 2022-05-10 10:30:32 -07:00
  • a4e32d8f3d Extract browsertest.LoginToUpstreamLDAP() integration test helper Ryan Richard 2022-05-09 15:43:36 -07:00
  • 831abc315e Update audit log proposal key names and timestamp format Ryan Richard 2022-05-09 14:45:18 -07:00
  • 6bb34130fe Add asymmetric crypto based client secret generation Monis Khan 2022-05-09 15:58:52 -04:00
  • 22aea6ab9d Address some small comments to make the doc more understandable Margo Crawford 2022-05-09 12:55:32 -07:00
  • 58f8a10919 Add data model and secret generation alternatives Monis Khan 2022-05-09 00:05:06 -04:00
  • 1c4ed8b404 Add recommendation for solving the audience confusion problem Monis Khan 2022-05-06 18:08:24 -04:00
  • afc73221d6 Updated versions in docs for v0.17.0 release Pinny 2022-05-06 19:28:56 +00:00
  • 4c44f583e9 Don't add pinniped_idp_name pinniped_idp_type params into upstream state Ryan Richard 2022-05-06 12:00:46 -07:00
  • 408e390094 Add more detail on how we should display errors Margo Crawford 2022-05-06 11:00:01 -07:00
  • ec22b5715b Add Pinniped favicon to login UI page 🦭 Ryan Richard 2022-05-05 14:46:07 -07:00
  • 6e6e1f4add Update login page CSS selectors in e2e test Ryan Richard 2022-05-05 13:56:38 -07:00
  • 00d68845c4 Add --flow to choose login flow in prepare-supervisor-on-kind.sh Ryan Richard 2022-05-05 13:42:23 -07:00
  • cffa353ffb Login page styling/structure for users, screen readers, passwd managers Ryan Richard 2022-05-05 13:12:06 -07:00
  • 6ca7c932ae Add unit test for rendering form_post response from POST /login Ryan Richard 2022-05-04 12:12:14 -07:00
  • b458cd43b9 Merge pull request #1159 from vmware-tanzu/fix-openldap-typo v0.17.0 Margo Crawford 2022-05-05 12:50:43 -07:00
  • 07a3faf449 Merge branch 'main' into fix-openldap-typo Margo Crawford 2022-05-05 10:51:09 -07:00
  • 329d41aac7 Add the full end to end test for ldap web ui Margo Crawford 2022-05-05 08:49:58 -07:00
  • 079908fb50 Update to reflect further conversations we've had Margo Crawford 2022-05-04 13:28:54 -07:00
  • 1a59b6a686 Update ROADMAP.md anjalitelang 2022-05-04 16:06:33 -04:00
  • eb891d77a5 Tiny fix: pinninpeds->pinnipeds Margo Crawford 2022-05-04 12:42:55 -07:00
  • 572474605f Merge pull request #1151 from vmware-tanzu/more_unit_tests_for_ldap_escaping Ryan Richard 2022-05-04 09:49:20 -07:00
  • 656f221fb7 Merge branch 'main' into ldap-login-ui Ryan Richard 2022-05-04 09:29:15 -07:00
  • a36688573b Merge pull request #1150 from vmware-tanzu/prepare_supervisor_on_kind_active_directory Ryan Richard 2022-05-04 09:16:13 -07:00
  • 2e031f727b Use security headers for the form_post page in the POST /login endpoint Ryan Richard 2022-05-03 16:46:09 -07:00
  • acc6c50e48 More unit tests for LDAP DNs which contain special chars Ryan Richard 2022-05-03 15:43:01 -07:00
  • 388cdb6ddd Fix bug where form was posting to the wrong path Margo Crawford 2022-05-03 15:18:38 -07:00
  • eaa87c7628 support AD in hack/prepare-supervisor-on-kind.sh Ryan Richard 2022-05-03 12:59:39 -07:00
  • d6e61012c6 Merge pull request #1149 from vmware-tanzu/update_kube_versions Ryan Richard 2022-05-02 15:35:49 -07:00
  • cc1f0b8db9 Merge pull request #1148 from vmware-tanzu/ldap_group_search_escape Ryan Richard 2022-05-02 14:44:45 -07:00
  • 90e88bb83c Update kube codegen versions Ryan Richard 2022-05-02 14:33:33 -07:00
  • 2ad181c7dd Merge branch 'main' into ldap_group_search_escape Ryan Richard 2022-05-02 13:49:55 -07:00
  • ee881aa406 Merge pull request #1146 from enj/enj/i/bump_0007 Mo Khan 2022-05-02 16:44:49 -04:00
  • c74dea6405 Escape special characters in LDAP DNs when used in search filters Ryan Richard 2022-05-02 13:37:32 -07:00
  • dfbc33b933 Apply suggestions from code review Ryan Richard 2022-05-02 09:47:09 -07:00
  • 69e5169fc5 Implement post_login_handler.go to accept form post and auth to LDAP/AD Ryan Richard 2022-04-29 16:01:51 -07:00
  • 56c8b9f884 Add recommendations to dynamic client proposal Ryan Richard 2022-04-29 12:48:03 -07:00
  • 646c6ec9ed Show error message on login page Margo Crawford 2022-04-29 10:36:13 -07:00
  • 2cdb55e7da Bump deps to latest and go mod compat to 1.17 Monis Khan 2022-04-28 15:31:50 -04:00
  • 453c69af7d Fix some errors and pass state as form element Margo Crawford 2022-04-28 12:07:04 -07:00
  • 07b2306254 Add basic outline of login get handler Margo Crawford 2022-04-28 09:11:51 -07:00
  • 77f016fb64 Allow browser_authcode flow for pinniped login command Margo Crawford 2022-04-27 08:53:53 -07:00
  • ae60d4356b Some refactoring of shared code between OIDC and LDAP browser flows Margo Crawford 2022-04-27 08:51:37 -07:00
  • 379a803509 when password header but not username is sent to password grant, error Margo Crawford 2022-04-26 16:46:58 -07:00
  • 65eed7e742 Implement login_handler.go to defer to other handlers Ryan Richard 2022-04-26 15:30:39 -07:00
  • eb1d3812ec Update authorization endpoint to redirect to new login page Margo Crawford 2022-04-26 12:51:56 -07:00
  • 8832362b94 WIP: Add login handler for LDAP/AD web login Margo Crawford 2022-04-25 16:41:55 -07:00