You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Telling a deployer that access control is their job leaves them to work out the details unaided, and the compatibility list from the access control task shows how much there is to get right. A worked sample would make it concrete.
Deliberately unscheduled. This has been raised before and met pushback, so it stays out of the dated documentation work rather than being allowed to hold it up. Raise it once the access control documentation has landed, when the published compatibility list is available as the argument for why a sample helps.
Shape if it goes ahead: a samples/behind-auth-proxy/ directory alongside the existing samples/air_routes/docker-compose.yaml, with a Compose file and a proxy configuration satisfying every constraint in the Access Control compatibility section, so it doubles as a regression check on that list.
Open question to answer before any work starts: whether shipping a sample reads as endorsing a particular product. That was the substance of the earlier pushback.
Related Issues
Related to Investigate approaches for adding OAuth2/OIDC support #1593, which asks whether to build OAuth2/OIDC support into Graph Explorer. This task is the opposite direction: running Graph Explorer behind something that already authenticates, with no product change.
Important
Internal only — this issue is maintained by the core team and is not accepting external contributions.
Telling a deployer that access control is their job leaves them to work out the details unaided, and the compatibility list from the access control task shows how much there is to get right. A worked sample would make it concrete.
Deliberately unscheduled. This has been raised before and met pushback, so it stays out of the dated documentation work rather than being allowed to hold it up. Raise it once the access control documentation has landed, when the published compatibility list is available as the argument for why a sample helps.
Shape if it goes ahead: a
samples/behind-auth-proxy/directory alongside the existingsamples/air_routes/docker-compose.yaml, with a Compose file and a proxy configuration satisfying every constraint in the Access Control compatibility section, so it doubles as a regression check on that list.Open question to answer before any work starts: whether shipping a sample reads as endorsing a particular product. That was the substance of the earlier pushback.
Related Issues
Important
Internal only — this issue is maintained by the core team and is not accepting external contributions.