[go: up one dir, main page]

Step-up auth: Show step-up auth for admin mode in active sessions [PART 1.1]

What does this MR do and why?

The active session page is important for users to see the active sessions, manage and revoke them.

As part of the step-up authentication for admin mode, it is important to identify the session that currently have the step-up authentication enabled.

This change ensures that users can easily identify which sessions have step-up authentication enabled, providing better transparency and security management.

🛠️ with ❤️ at Siemens

References

MR acceptance checklist

Please evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

MR Checklist (@gerardo-navarro)

Screenshots or screen recordings

Here is the screencast to demonstrate the feature:

Before After
image image

How to set up and validate locally

Part 1: Configure step-up auth in Keycloak

  1. Follow the steps for configuring step-up auth as decribed in a previous MR description (Part 1)

Part 2: Prepare your local GitLab gdk instance

  1. Follow the steps for configuring step-up auth as decribed in a previous MR description (Part 2)

Part 3: Observe active sessions in separate browser window

  1. Go to the usual sign in page: http://gdk.test:3000/users/sign_in
  2. Go to your User Settings > Active Sessions page.
  3. You should see your current session 👍
  4. Now continuously refresh the page after the steps in Part 4 in order to see the changes

Part 4: Test the step-up auth for admin mode

  1. Open another private browser window (fresh session); do not use the same browser as in Part 3 to ensure that you have an isolated session
  2. Go to the usual sign in page: http://gdk.test:3000/users/sign_in
  3. Sign in via Keycloak via username and password
  4. After a successful sign in, the user will be redirected to it's dashboard
  5. Look at the active session page (in the other browser) and you should see an additinoal active session
  6. Go to the reauthentication page for the admin area: http://gdk.test:3000/admin/session/new (this should be possible because the user is also an admin)
  7. Sign in with the button "[OIDC] Keycloak" and fulfill the step-up authentication challenge
  8. You should now be inside the admin area 😄
  9. Look at the active session page (in the other browser) and see that one active session contains the information "with Step-up Authentication" and "with Admin Mode"

Related to #474650 #545094

Edited by Gerardo Navarro

Merge request reports

Loading