-
Story
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
True
-
-
False
-
XCMSTRAT-600 - More Secure Auth Flows in OCM / ROSA CLIs
-
-
Context:
Offline tokens support should have been already deprecated, but it turned out OCM cannot completely drop support of offline tokens since some users are not able to move to stop using them and move to SSO login.
For this reason, the original plan which was:
- To show a deprecation message during the migration period
- Stop showing offline tokens method , show SSO login method instead
is not relevant any more.
The new goal is to encourage users to use the more secure method SSO login method over using offline tokens.
Changes are required in 2 places:
- The login page linked from downloads page https://console.redhat.com/openshift/token
- Login section (step 2) at ROSA getting started page. https://console.redhat.com/openshift/create/rosa/getstarted
In addition -
The feature flag (cli-sso-authorization) should be removed when this work is completed.
Draft UX design: https://www.figma.com/design/t6KHiullNe1WniS7XjBtHc/OCM-Tokens?node-id=86-72573&t=3xHv6GPLUoVC0Nwt-1
Status 01/30: UX design is being finalized
- relates to
-
OCMUI-2387 [Tokens] Update deprecation messaging on 'Load Token' page
-
- Closed
-