Story #8109
Does authentication token need to include group information?
Status:
New
Priority:
Normal
Assignee:
Category:
Authentication, Authorization
Target version:
-
Start date:
2017-06-06
Due date:
% Done:
0%
Story Points:
Sprint:
Description
Currently when portal generates the authentication token, it doesn't include the group information in it in order to make the token short. So when an entity tries to authorize the token, it has to look up the group information in order to make the group authorization mechanism work. The lookup process has to access multiple places, e.g., the dataone cn, an ldap server, and et al. This seems an overhead.
History
#1 Updated by Jing Tao over 7 years ago
- Tracker changed from Feature to Story
- Subject changed from Authentication token needs to include group information to Does authentication token need to include group information?
#2 Updated by Dave Vieglais almost 7 years ago
- Sprint set to Infrastructure backlog