Skip to content

Conversation

@themr0c
Copy link
Member

@themr0c themr0c commented Jun 13, 2025

Reorganize the content in a more logical way, for consistency with #1224 (consistent user flow, consistent formatting and sentences).

IMPORTANT: Do Not Merge - To be merged by Docs Team Only

Version(s): 1.7

Issue:
https://issues.redhat.com/browse/RHIDP-7833
https://issues.redhat.com/browse/RHIDP-7636

Preview: https://redhat-developer.github.io/red-hat-developers-documentation-rhdh/pr-1227/authentication/#enabling-user-authentication-with-microsoft-azure

@rhdh-bot
Copy link
Collaborator

rhdh-bot commented Jun 13, 2025

@themr0c themr0c force-pushed the RHIDP-7833 branch 2 times, most recently from a97d361 to 29a77fe Compare June 13, 2025 14:42
Signed-off-by: Fabrice Flore-Thébault <[email protected]>
Copy link
Member

@kim-tsao kim-tsao left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we need to specify two apps; one for auth and one for msgraph. The app for msgraph requires application level permissions only. See upstream docs. I will discuss this in the team call tomorrow and get back to you.

@themr0c
Copy link
Member Author

themr0c commented Jun 26, 2025

@kim-tsao What would be the reason for two separate apps? Security and separation of concerns? Drawback for the user will be more complexity (set up two apps rather than one), I'd like to avoid it if it is not necessary.

@JessicaJHee
Copy link
Member

@kim-tsao What would be the reason for two separate apps? Security and separation of concerns? Drawback for the user will be more complexity (set up two apps rather than one), I'd like to avoid it if it is not necessary.

@themr0c we looked into this further and found that one app is enough. When the user signs in through the authentication flow, they are provided an access token ONLY with delegated permissions, while the backend catalog plugin will have the granted application permissions. So we are good to use one app as long as the delegated/application permissions are set up correctly.

@themr0c
Copy link
Member Author

themr0c commented Jun 27, 2025

@JessicaJHee @kim-tsao can you formally put your seal of approval?

@themr0c themr0c added Technical review done ⛅ Any procedure has been succesfully tested and removed Technical review needed 🔩 Test all the procedures labels Jun 27, 2025
Copy link
Member

@JessicaJHee JessicaJHee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thank you @themr0c for all your work!

Copy link
Member

@Gerry-Forde Gerry-Forde left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me.

@themr0c themr0c merged commit dc8293c into redhat-developer:main Jul 7, 2025
4 of 5 checks passed
@themr0c themr0c deleted the RHIDP-7833 branch August 5, 2025 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants