-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
📖 Capture Alpha Users's Justice identity in order to prepare for migration to new identity strategy #3605
📖 Capture Alpha Users's Justice identity in order to prepare for migration to new identity strategy #3605
Comments
27/3/24 TODO
|
2/4/24 It is only enabled for superusers, so normal users logging in to the dev site (there are some that are using it for Bedrock) will not see the message about authenticating with their justice identity. Superusers will, however attempting to authenticate will cause a 500 error, as there are missing EntraID secrets, which requires #3868 to be completed to add. Therefore, I have moved this ticket to blocked. |
4/4/24 |
Helm chart updated to set the AZURE_CLIENT_SECRET env. |
User Story
As as AP engineer, I would like to start collecting AP users' justice identity so we can start preparing to the roll-out of our new identity strategy.
Value / Purpose
A single identity across our estate is the ultimate goal, not only for security reasons but also for easing onboarding onto the platform. All MOJ employees have or could get justice accounts but not everyone uses or needs Github accounts. Linking AP auth to justice identity will help expand our reach.
Useful Contacts
Michael Collins, Julia Lawrence
User Types
AP Users
Hypothesis
If we begin collecting this information now, we will be in a better position to migrate people when the time is right.
Proposal
Additional Information
Potential questions:
Should we allow new users to register with their justice identity going forward? Is it worth implementing that at the same time so we can lower the number of users we eventually need to migrate?
For QS:
Should we make providing the justice identity as a prereq for new QS accesss? (New UI only allows justice authentiation?)
Things to think about:
Deferral?
"I don't have a justice account?" (More likely with P&A folks)
Definition of Done
The text was updated successfully, but these errors were encountered: