Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

User Story: User administrating multiple services through a portal #5

Open
kdeqc opened this issue Oct 8, 2021 · 2 comments
Open

Comments

@kdeqc
Copy link
Contributor

kdeqc commented Oct 8, 2021

User story

I've purchased multiple services to help me run my web site (say content management, ecommerce, email management,, web analytics, and chat services). To administer the services, I go to a login page to a portal site where I login with my own credentials for the portal. Each service has its own credential system, so the portal is using identity federation instead of a simple single-credential SSO setup.

Context of the story

This is an enterprise authentication flow.

Should this be considered sanctioned or unsanctioned tracking?

TBD

Explicit list of parties involved

  • user
  • browser
  • enterprise IdP
  • service RPs

Complicating characteristics

Whether or not all of the services are owned by the same organization or not. In this case, let's assume all of the services are owned by the same organization.

Additional information

We agreed that the technical implementation details matter - so in this use case, let's assume this is a standard OAuth setup like:

oauth

For the purpose of this use case, let's also assume that this is using a global identifier for the organization as a whole as well.

@hlflanagan
Copy link
Contributor

Would this scenario require the use of 3p cookies?

@hlflanagan
Copy link
Contributor

Discussed on 2021-12-10 fedidcg call

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants