deft/tracker.org

2555 lines
90 KiB
Org Mode
Raw Normal View History

2021-01-21 13:20:59 +00:00
* 2021
2021-01-20 15:08:03 +00:00
** 2021-W03
2021-01-21 13:20:59 +00:00
*** 2021-01-21 Thursday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS code jwt-service :work:
2021-01-21 13:20:59 +00:00
[2021-01-21 Thu 14:19]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/inbox.org::*prepare standup bulletpoints for meeting][prepare standup bulletpoints for meeting]]
2021-01-22 08:54:04 +00:00
*** 2021-01-22 Friday
2021-01-22 17:49:44 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-01-22 Fri 18:49]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+------+-----------------------------+--------+---+------+------|
| | | *Total time* | *8:56* | | | |
|------------------------+------+-----------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-22 Friday][2021-01-22 Friday]] | | | 8:56 | |
| [2021-01-22 Fri 09:52] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*refacto jwt-service][refacto jwt-service]] | | | | 8:56 |
#+END:
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS refacto jwt-service :work:
2021-01-22 08:54:04 +00:00
:LOGBOOK:
2021-01-22 17:49:44 +00:00
CLOCK: [2021-01-22 Fri 09:53]--[2021-01-22 Fri 18:49] => 8:56
2021-01-22 08:54:04 +00:00
:END:
[2021-01-22 Fri 09:52]
- ref ::
2021-01-25 09:16:52 +00:00
** 2021-W04
2021-02-01 13:48:56 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-02-01 Mon 14:47]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+--------------------+---------------------------------------------+---------+-------+-------+------|
| | | *Total time* | *41:38* | | | |
|------------------------+--------------------+---------------------------------------------+---------+-------+-------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-W04][2021-W04]] | | 41:38 | | |
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-25 Monday][2021-01-25 Monday]] | | | 7:28 | |
| [2021-01-25 Mon 19:23] | work, meeting | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Posture Onboarding][Posture Onboarding]] | | | | 0:38 |
| [2021-01-25 Mon 15:04] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*cleanup jwt extract feedback][cleanup jwt extract feedback]] | | | | 4:19 |
| [2021-01-25 Mon 14:36] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*refacto JWT extraction reviews][refacto JWT extraction reviews]] | | | | 0:15 |
| [2021-01-25 Mon 10:16] | work, chat | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*morning chat issues org][morning chat issues org]] | | | | 2:16 |
| [2021-01-26 Tue 19:06] | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-26 Tuesday][2021-01-26 Tuesday]] | | | 9:03 | |
| [2021-01-26 Tue 10:36] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Victors UncaughtExceptionHandler][Victors UncaughtExceptionHandler]] | | | | 8:29 |
| [2021-01-26 Tue 10:16] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*PR review][PR review]] | | | | 0:06 |
| [2021-01-26 Tue 09:47] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Weekly meeting Presentation][Weekly meeting Presentation]] | | | | 0:28 |
| [2021-01-27 Wed 22:01] | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-27 Wednesday][2021-01-27 Wednesday]] | | | 10:59 | |
| [2021-01-27 Wed 18:22] | work, meeting | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration workflow presentation][CSA Migration workflow presentation]] | | | | 2:10 |
| [2021-01-27 Wed 17:26] | interruption, work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Helping Jessica Bair about client][Helping Jessica Bair about client]] | | | | 0:54 |
| [2021-01-27 Wed 16:01] | work, meeting | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*weekly dev meeting][weekly dev meeting]] | | | | 1:25 |
| [2021-01-27 Wed 12:07] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration notes preparation][CSA Migration notes preparation]] | | | | 3:54 |
| [2021-01-27 Wed 09:31] | work, chat | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*morning chat][morning chat]] | | | | 2:36 |
| [2021-01-28 Thu 18:09] | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-28 Thursday][2021-01-28 Thursday]] | | | 8:09 | |
| [2021-01-28 Thu 09:52] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration API PoC preparation][CSA Migration API PoC preparation]] | | | | 8:09 |
| [2021-01-29 Fri 17:46] | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-29 Friday][2021-01-29 Friday]] | | | 5:59 | |
| [2021-01-29 Fri 15:47] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*create Client for Vitalii in TEST][create Client for Vitalii in TEST]] | | | | 1:59 |
| [2021-01-29 Fri 15:46] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*provisionning API][provisionning API]] | | | | 4:00 |
#+END:
2021-01-25 09:16:52 +00:00
*** 2021-01-25 Monday
2021-03-08 18:01:11 +00:00
**** MEETING Posture Onboarding :work:meeting:
2021-01-25 18:25:13 +00:00
:LOGBOOK:
2021-01-26 08:40:47 +00:00
CLOCK: [2021-01-25 Mon 19:24]--[2021-01-25 Mon 20:02] => 0:38
2021-01-25 18:25:13 +00:00
:END:
[2021-01-25 Mon 19:23]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*cleanup jwt extract feedback][cleanup jwt extract feedback]]
***** Notes
2021-01-25 18:33:26 +00:00
Martin, Trapani, Didi, Jyoti, Elias, Mirabell, Guillaume
2021-01-25 18:37:20 +00:00
@Martin:
2021-01-25 18:33:26 +00:00
I am a customer of SecureX
2021-01-25 18:35:01 +00:00
Sources (inTune, AMP, Custom, JAMF, Duo, Meraki)
Creating the inventory on their behalf.
Active AMP, should be onboarded in SecureX.
2021-01-25 18:36:09 +00:00
Onboard device managers, Meraki, etc...
Into "my" SecureX Tenant.
Extra credit if we can do this with OAuth2.
Most important make a connection here.
- email exchange.
2021-01-25 18:37:20 +00:00
@Jyoti
2021-01-25 18:39:33 +00:00
@Martin
2021-01-25 18:37:20 +00:00
2021-01-25 18:39:33 +00:00
Vault service and what is authorized between services.
APIs underneath
2021-01-25 18:37:20 +00:00
2021-01-25 18:46:49 +00:00
@Didi
2021-01-25 18:42:11 +00:00
webhook to push changes.
Ask the vault. Return keys, etc...
2021-01-25 18:43:38 +00:00
We need continuation.
2021-01-25 18:46:49 +00:00
@Didi
2021-01-25 18:37:20 +00:00
2021-01-25 18:46:49 +00:00
Google, trusts, etc...
2021-01-25 18:50:34 +00:00
@Martin
onboarding, revocation,
What about notification?
@Didi that's the idea of continuous data flow.
2021-01-25 18:51:51 +00:00
Bidirectional webhooks.
Some services will need to have webhooks.
Orbital webehook is a very good example.
You go into orbital, you register webhook.
And webhook is triggered.
2021-01-25 19:02:08 +00:00
@Elias to Didi
use cases?
@Martin
- continuous flow of data? need to describe use cases.
2021-03-08 18:01:11 +00:00
**** DONE cleanup jwt extract feedback :work:
2021-01-25 18:25:13 +00:00
:LOGBOOK:
CLOCK: [2021-01-25 Mon 15:04]--[2021-01-25 Mon 19:23] => 4:19
:END:
[2021-01-25 Mon 15:04]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/inbox.org::*commander les fruits & légumes][commander les fruits & légumes]]
2021-03-08 18:01:11 +00:00
**** DONE refacto JWT extraction reviews :work:
2021-01-25 13:37:57 +00:00
:LOGBOOK:
2021-01-25 13:52:37 +00:00
CLOCK: [2021-01-25 Mon 14:36]--[2021-01-25 Mon 14:51] => 0:15
2021-01-25 13:37:57 +00:00
:END:
[2021-01-25 Mon 14:36]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*morning chat issues org][morning chat issues org]]
2021-01-25 09:16:52 +00:00
**** CHAT morning chat issues org :work:chat:
:LOGBOOK:
2021-01-25 13:37:57 +00:00
CLOCK: [2021-01-25 Mon 10:00]--[2021-01-25 Mon 12:16] => 2:16
2021-01-25 09:16:52 +00:00
:END:
[2021-01-25 Mon 10:16]
- ref ::
2021-01-26 08:40:47 +00:00
*** 2021-01-26 Tuesday
2021-01-29 14:47:41 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-01-26 Tue 19:06]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+--------------+------------------------------------------+--------+---+------+------|
| | | *Total time* | *9:03* | | | |
|------------------------+--------------+------------------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-26 Tuesday][2021-01-26 Tuesday]] | | | 9:03 | |
| [2021-01-26 Tue 10:36] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Victors UncaughtExceptionHandler][Victors UncaughtExceptionHandler]] | | | | 8:29 |
| [2021-01-26 Tue 10:16] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*PR review][PR review]] | | | | 0:06 |
| [2021-01-26 Tue 09:47] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Weekly meeting Presentation][Weekly meeting Presentation]] | | | | 0:28 |
#+END:
2021-03-08 18:01:11 +00:00
**** REVIEW Victors UncaughtExceptionHandler :work:review:
2021-01-26 08:48:39 +00:00
:LOGBOOK:
2021-01-29 14:47:41 +00:00
CLOCK: [2021-01-26 Tue 10:37]--[2021-01-26 Tue 19:06] => 8:29
:END:
[2021-01-26 Tue 10:36]
2021-03-08 18:01:11 +00:00
**** GEEK Try to write JS warn in dashboard :perso:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-26 Tue 10:22]--[2021-01-26 Tue 10:32] => 0:10
:END:
[2021-01-26 Tue 10:22]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Weekly meeting Presentation][Weekly meeting Presentation]]
2021-03-08 18:01:11 +00:00
**** REVIEW PR review :work:review:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-26 Tue 10:16]--[2021-01-26 Tue 10:22] => 0:06
:END:
[2021-01-26 Tue 10:16]
2021-03-08 18:01:11 +00:00
**** DONE Weekly meeting Presentation :work:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-26 Tue 09:47]--[2021-01-26 Tue 10:15] => 0:28
2021-01-26 08:48:39 +00:00
:END:
[2021-01-26 Tue 09:47]
2021-01-29 14:47:41 +00:00
***** Weekly Status
- Extracted a JWT service
- Added audiences as an array. Does not appear to break anything
- Updated the SSE OIDC Clients to support CSA Migration
- Contacted QA for testing CSA Migration, Houman will probably ping me today.
+ Testing CSA Migration
***** Tech notes worth seeing by the team
****** naming conventions
After a few discussions choose a project/ns naming convention for the
=iroh-service= lein template.
We do not really have one.
Selected this conventions because it is:
- shorter than most actual used conventions
- iroh specific to make it clear a ns is iroh related.
Need to find files via path, not just its name. Sounds ok to me.
For an example look at the jwt service:
- =project.clj=: ~(defproject iroh/foo ,,,,)~
- =src/iroh/foo/service.clj=
=> ~(ns iroh.foo.service ,,,)~
- =src/iroh/foo/web_service.clj=
=> ~(ns iroh.foo.web-service ,,,)~
- =test/iroh/foo/service/test_helpers.clj=
=> ~(ns iroh.foo.service.test-helpers ,,,)~
I don't think we should move the existing code to the new conventions yet.
But new services should probably try to follow this convention.
****** Refacto Plan: Testing web services and cycles.
Example:
#+begin_src clojure
(deftest my-web-service-test
(tk-test app svc-helper
(let [{:keys [mk-jwt svc-get client-post]}
(init-tst-state app "/iroh/my-service")
jwt (mk-jwt {})
jwt-admin (mk-jwt {:role roles/admin})]
(check-status 403 (svc-get "/sub-route" jwt {}))
(check-status 200 (svc-get "/sub-route" jwt-admin {}))
(check-status 200 (client-post "/sub-route" jwt
{:form-parms {:foo "bar"}})))))
#+end_src
See a few =init-tst-state= examples which uses =get-jetty-port=,
=mk-http-callers=, =iroh-web.test-helpers.core/gen-jwt=.
Takes care of:
- starting the web app on a random port.
- providing functions to make http call
- narrowed to your service (svc-get, svc-post, etc...)
- narrowed only the localhost:PORT (client-get, client-post, etc...)
- providing a jwt generator.
2021-03-08 18:01:11 +00:00
**** GEEK org-fc conf for doom-emacs :perso:
2021-01-26 08:40:47 +00:00
:LOGBOOK:
2021-01-26 08:48:39 +00:00
CLOCK: [2021-01-26 Tue 09:39]--[2021-01-26 Tue 09:47] => 0:08
2021-01-26 08:40:47 +00:00
:END:
[2021-01-26 Tue 09:39]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/inbox.org::*bouteilles][bouteilles]]
2021-01-29 14:47:41 +00:00
*** 2021-01-27 Wednesday
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-01-27 Wed 22:01]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+--------------------+---------------------------------------------+---------+---+-------+------|
| | | *Total time* | *10:59* | | | |
|------------------------+--------------------+---------------------------------------------+---------+---+-------+------|
| | | \_ [[file:/Users/yaesposi/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-27 Wednesday][2021-01-27 Wednesday]] | | | 10:59 | |
| [2021-01-27 Wed 18:22] | work, meeting | \_ [[file:/Users/yaesposi/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration workflow presentation][CSA Migration workflow presentation]] | | | | 2:10 |
| [2021-01-27 Wed 17:26] | interruption, work | \_ [[file:/Users/yaesposi/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Helping Jessica Bair about client][Helping Jessica Bair about client]] | | | | 0:54 |
| [2021-01-27 Wed 16:01] | work, meeting | \_ [[file:/Users/yaesposi/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*weekly dev meeting][weekly dev meeting]] | | | | 1:25 |
| [2021-01-27 Wed 12:07] | work | \_ [[file:/Users/yaesposi/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration notes preparation][CSA Migration notes preparation]] | | | | 3:54 |
| [2021-01-27 Wed 09:31] | work, chat | \_ [[file:/Users/yaesposi/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*morning chat][morning chat]] | | | | 2:36 |
#+END:
2021-03-08 18:01:11 +00:00
**** MEETING CSA Migration workflow presentation :work:meeting:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-27 Wed 18:22]--[2021-01-27 Wed 20:32] => 2:10
:END:
[2021-01-27 Wed 18:22]
AMP accounts, TG accounts, SSE devices, Orbital
Prepare a reset system to reset to before migration.
2021-03-08 18:01:11 +00:00
**** DONE Helping Jessica Bair about client :interruption:work:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-27 Wed 17:27]--[2021-01-27 Wed 18:21] => 0:54
:END:
[2021-01-27 Wed 17:26]
2021-03-08 18:01:11 +00:00
**** MEETING weekly dev meeting :work:meeting:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-27 Wed 16:01]--[2021-01-27 Wed 17:26] => 1:25
:END:
[2021-01-27 Wed 16:01]
- Talk about dahsboard
2021-03-08 18:01:11 +00:00
**** DONE CSA Migration notes preparation :work:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-27 Wed 12:07]--[2021-01-27 Wed 16:01] => 3:54
:END:
[2021-01-27 Wed 12:07]
- [[https://github.com/threatgrid/iroh/issues/4203][Main Epic]]
- https://cisco.invisionapp.com/share/MBYJ09WXP3F#/screens/429343341
- [[file:~/dev/iroh/services/iroh-auth/doc/developer.org::#sxso-migration][SxSO Migration IROH Auth dev docs]]
**** CHAT morning chat :work:chat:
:LOGBOOK:
CLOCK: [2021-01-27 Wed 09:31]--[2021-01-27 Wed 12:07] => 2:36
:END:
[2021-01-27 Wed 09:31]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*PR review][PR review]]
*** 2021-01-28 Thursday
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-01-28 Thu 18:09]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+------+-------------------------------------------+--------+---+------+------|
| | | *Total time* | *8:09* | | | |
|------------------------+------+-------------------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-28 Thursday][2021-01-28 Thursday]] | | | 8:09 | |
| [2021-01-28 Thu 09:52] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration API PoC preparation][CSA Migration API PoC preparation]] | | | | 8:09 |
#+END:
2021-03-08 18:01:11 +00:00
**** DONE CSA Migration API PoC preparation :work:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-29 Fri 15:46]--[2021-01-29 Fri 15:46] => 0:00
CLOCK: [2021-01-28 Thu 10:50]--[2021-01-28 Thu 18:09] => 7:19
CLOCK: [2021-01-28 Thu 09:52]--[2021-01-28 Thu 10:42] => 0:50
:END:
[2021-01-28 Thu 09:52]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration workflow presentation][CSA Migration workflow presentation]]
*** 2021-01-29 Friday
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
2021-01-29 16:47:17 +00:00
#+CAPTION: Clock summary at [2021-01-29 Fri 17:46]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+------+-------------------------------------------+--------+---+------+------|
| | | *Total time* | *5:59* | | | |
|------------------------+------+-------------------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-01-29 Friday][2021-01-29 Friday]] | | | 5:59 | |
| [2021-01-29 Fri 15:47] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*create Client for Vitalii in TEST][create Client for Vitalii in TEST]] | | | | 1:59 |
| [2021-01-29 Fri 15:46] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*provisionning API][provisionning API]] | | | | 4:00 |
2021-01-29 14:47:41 +00:00
#+END:
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS create Client for Vitalii in TEST :work:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
2021-01-29 16:47:17 +00:00
CLOCK: [2021-01-29 Fri 15:47]--[2021-01-29 Fri 17:46] => 1:59
2021-01-29 14:47:41 +00:00
:END:
[2021-01-29 Fri 15:47]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*provisionning API][provisionning API]]
2021-03-08 18:01:11 +00:00
**** DONE provisionning API :work:
2021-01-29 14:47:41 +00:00
:LOGBOOK:
CLOCK: [2021-01-29 Fri 14:16]--[2021-01-29 Fri 15:46] => 1:30
CLOCK: [2021-01-29 Fri 09:46]--[2021-01-29 Fri 12:16] => 2:30
:END:
[2021-01-29 Fri 15:46]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration API PoC preparation][CSA Migration API PoC preparation]]
2021-02-01 09:37:09 +00:00
** 2021-W05
*** 2021-02-01 Monday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS enforce whoami db check to sync users. :work:
2021-02-01 16:21:05 +00:00
:LOGBOOK:
2021-02-02 08:49:25 +00:00
CLOCK: [2021-02-01 Mon 17:19]--[2021-02-01 Mon 18:19] => 1:00
2021-02-01 16:21:05 +00:00
:END:
[2021-02-01 Mon 17:19]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*fix iroh-auth doc regarding jwks][fix iroh-auth doc regarding jwks]]
2021-03-08 18:01:11 +00:00
**** DONE fix iroh-auth doc regarding jwks :work:
2021-02-01 09:37:09 +00:00
:LOGBOOK:
2021-02-01 13:54:47 +00:00
CLOCK: [2021-02-01 Mon 10:35]--[2021-02-01 Mon 14:53] => 4:18
2021-02-01 09:37:09 +00:00
:END:
[2021-02-01 Mon 10:35]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/inbox.org::*Améliorer son Anglais (bis) (italki)][Améliorer son Anglais (bis) (italki)]]
2021-02-02 08:49:25 +00:00
*** 2021-02-02 Tuesday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS Testing CSA Migration :work:
2021-02-02 08:49:25 +00:00
:LOGBOOK:
2021-02-03 09:12:19 +00:00
CLOCK: [2021-02-02 Tue 10:42]--[2021-02-03 Wed 10:11] => 23:29
2021-02-02 09:44:07 +00:00
:END:
[2021-02-02 Tue 10:42]
2021-03-08 18:01:11 +00:00
**** DONE morning routine :work:
2021-02-02 09:44:07 +00:00
:LOGBOOK:
CLOCK: [2021-02-02 Tue 09:48]--[2021-02-02 Tue 10:42] => 0:54
2021-02-02 08:49:25 +00:00
:END:
[2021-02-02 Tue 09:48]
2021-02-03 09:12:19 +00:00
*** 2021-02-03 Wednesday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS CORS headers bug :work:
2021-02-03 13:43:30 +00:00
:LOGBOOK:
2021-02-04 09:25:26 +00:00
CLOCK: [2021-02-03 Wed 14:42]--[2021-02-04 Thu 10:24] => 19:42
2021-02-03 13:43:30 +00:00
:END:
[2021-02-03 Wed 14:42]
- ref ::
2021-03-08 18:01:11 +00:00
**** DONE IdP Migration Testing :work:
2021-02-03 09:12:19 +00:00
:LOGBOOK:
CLOCK: [2021-02-03 Wed 10:11]--[2021-02-03 Wed 10:11] => 0:00
:END:
[2021-02-03 Wed 10:11]
2021-02-03 09:13:22 +00:00
Note quite complex workflow but worked as expected.
Had the "You are in the middle of an Invitation" prompt.
2021-02-04 09:25:26 +00:00
*** 2021-02-04 Thursday
2021-02-04 09:26:32 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
2021-02-05 08:50:57 +00:00
#+CAPTION: Clock summary at [2021-02-04 Thu 19:00]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+---------------+------------------------------------------+--------+---+------+------|
| | | *Total time* | *9:46* | | | |
|------------------------+---------------+------------------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-02-04 Thursday][2021-02-04 Thursday]] | | | 9:46 | |
| [2021-02-04 Thu 17:32] | work, meeting | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*didi Posture][didi Posture]] | | | | 1:28 |
| [2021-02-04 Thu 10:25] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*morning review tour][morning review tour]] | | | | 7:07 |
| [2021-02-04 Thu 10:24] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*test and discussion about CSA Migration][test and discussion about CSA...]] | | | | 1:11 |
2021-02-04 09:26:32 +00:00
#+END:
2021-03-08 18:01:11 +00:00
**** MEETING didi Posture :work:meeting:
2021-02-04 16:33:08 +00:00
:LOGBOOK:
2021-02-05 08:50:57 +00:00
CLOCK: [2021-02-04 Thu 17:32]--[2021-02-04 Thu 19:00] => 1:28
2021-02-04 16:33:08 +00:00
:END:
[2021-02-04 Thu 17:32]
2021-02-04 09:26:32 +00:00
2021-02-04 16:33:08 +00:00
Best user experience, etc..
2021-02-04 17:12:32 +00:00
Create a response issue about OAuth2/OIDC/trusted clients.
2021-02-04 17:25:02 +00:00
#+begin_src
{
"scopes": [
"openid","profile"
],
"description": "string",
"redirects": [
"https://127.0.0.1:5443/callback"
],
"availability": "everyone",
"name": "int-posture-test",
"grants": [
"auth-code"
],
"audiences": [
"posture"
]
}
#+end_src
2021-03-08 18:01:11 +00:00
**** REVIEW morning review tour :work:review:
2021-02-04 09:25:26 +00:00
:LOGBOOK:
2021-02-04 16:33:08 +00:00
CLOCK: [2021-02-04 Thu 10:25]--[2021-02-04 Thu 17:32] => 7:07
2021-02-04 09:25:26 +00:00
:END:
[2021-02-04 Thu 10:25]
2021-03-08 18:01:11 +00:00
**** DONE test and discussion about CSA Migration :work:
2021-02-04 09:25:26 +00:00
:LOGBOOK:
CLOCK: [2021-02-04 Thu 09:14]--[2021-02-04 Thu 10:25] => 1:11
:END:
[2021-02-04 Thu 10:24]
2021-02-05 08:50:57 +00:00
*** 2021-02-05 Friday
2021-02-05 12:59:35 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-02-05 Fri 13:58]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+--------------+-------------------------------------------+--------+---+------+------|
| | | *Total time* | *2:59* | | | |
|------------------------+--------------+-------------------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-02-05 Friday][2021-02-05 Friday]] | | | 2:59 | |
| | work, chat | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Team discussion][Team discussion]] | | | | 0:36 |
| [2021-02-05 Fri 11:34] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Ambrose review][Ambrose review]] | | | | 0:28 |
| [2021-02-05 Fri 09:49] | work, chat | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Client creation review with Diana][Client creation review with Diana]] | | | | 1:55 |
#+END:
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS playing? :work:
2021-02-05 12:58:20 +00:00
:LOGBOOK:
2021-02-08 11:10:26 +00:00
CLOCK: [2021-02-05 Fri 13:57]--[2021-02-05 Fri 14:57] => 1:00
2021-02-05 12:58:20 +00:00
:END:
[2021-02-05 Fri 13:57]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Ambrose review][Ambrose review]]
2021-02-05 12:59:35 +00:00
**** CHAT Team discussion :work:chat:
:LOGBOOK:
CLOCK: [2021-02-05 Fri 11:42]--[2021-02-05 Fri 12:18] => 0:36
2021-03-08 18:01:11 +00:00
**** REVIEW Ambrose review :work:review:
2021-02-05 10:35:37 +00:00
:LOGBOOK:
2021-02-05 10:43:57 +00:00
CLOCK: [2021-02-05 Fri 11:14]--[2021-02-05 Fri 11:42] => 0:28
2021-02-05 10:35:37 +00:00
:END:
[2021-02-05 Fri 11:34]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Client creation review with Diana][Client creation review with Diana]]
2021-02-05 08:50:57 +00:00
**** CHAT Client creation review with Diana :work:chat:
:LOGBOOK:
2021-02-05 10:43:57 +00:00
CLOCK: [2021-02-05 Fri 09:19]--[2021-02-05 Fri 11:14] => 1:55
2021-02-05 08:50:57 +00:00
:END:
[2021-02-05 Fri 09:49]
- ref :: https://ui-staging.int.iroh.site/platform/sx-help-docs-1-66-db/help/settings-api-clients
2021-02-05 08:53:48 +00:00
Hi Diana,
2021-02-05 09:04:59 +00:00
Thanks for reaching out.
2021-02-05 09:06:26 +00:00
While reviewing the doc, I also checked the second screenshot.
I think it should be changed by another one.
The screenshot was made by a super user, so the scopes displayed are
private one that none of our customer will ever see.
2021-02-05 09:08:43 +00:00
2021-02-05 09:17:41 +00:00
The main difference between a "Client Credentials Grant Client"
2021-02-05 09:16:41 +00:00
and an "Authorization Code Grant Client" (those are the technically correct
2021-02-05 09:28:42 +00:00
and kind of bad names for the two different kind of clients) is that:
2021-02-05 09:16:41 +00:00
2021-02-05 09:28:42 +00:00
1. /Client Credentials Grant Client/ are for your user only. Also you do
not need to own a website.
2021-02-05 09:16:41 +00:00
2. /Authorization Code Grant Client/ can be used to ask other users to
2021-02-05 09:28:42 +00:00
trust your application. You need to have a website to host your
application.
2021-02-05 09:17:41 +00:00
2021-02-05 09:28:42 +00:00
The reason why a customer would want to configure an /Authorization Code
Grant Client/ could be:
2021-02-05 09:17:41 +00:00
1. The customer follow a documentation provided by Cisco to integrate a
on-premise product. In that case, the customer will probably need to
2021-02-05 09:27:30 +00:00
only select a /client-preset/ and enter a custom /Redirect URL/.
2021-02-05 09:17:41 +00:00
2. The customer want to build an integration with SecureX. In this case
this will be an advanced usage and the creator will probably be a developer.
In this case the advanced developer doc should be mentionned for that customer.
https://visibility.amp.cisco.com/iroh/doc/iroh-auth/
2021-02-05 09:21:38 +00:00
So both kind of clients are sufficiently different that I think the section
about "Using API Client Credentials to Get Access Token" should be moved
just after the API client creation section and before OAuth Code client
creation section.
Also Explaining how to retrieve the access token from a Authorization Code
Grant client is quite a technically advanced topic. This is why I would
advise to directly provide a link to the advanced developer doc (the one
inside IROH not the Cisco DEVNET; thus
https://visibility.amp.cisco.com/iroh/doc/iroh-auth/)
2021-02-05 09:31:13 +00:00
So I think it is important to mention important limitations about those
client creations.
There is a notion of "Auto-approved clients".
2021-02-05 09:32:36 +00:00
So a customer will be able to create clients but if some criteria are not
2021-02-05 09:33:49 +00:00
met the client will be disabled until an IROH admin approve the client.
I think this should probably need to be talked about with someone in the
2021-02-05 09:34:50 +00:00
UI/UX team. This system was very convenient for our advanced usage, but I
don't know how to handle that nicely in the UI.
So here are (some) of the constraints a newly client must have to be
automatically approved:
1. The URL must start with =https://=
2. The URL must not contain any wildcard =*=
2021-02-05 09:36:19 +00:00
3. The Availabily must not be =everyone=
2021-02-05 09:38:28 +00:00
4. The client contain some restricted scope (this should never occurs as
the UI take care to show only scopes not subject to restriction)
5. The client must not be =public= (the UI does not appear to provide the
2021-02-05 09:36:19 +00:00
confidential vs public option)
2021-02-05 09:40:07 +00:00
6. The client configure a list of specific =audiences= (the UI does not
2021-02-05 09:38:28 +00:00
appear to provide any mean to configure this field)
2021-02-05 09:40:07 +00:00
I think for the documentation perspective we should only be concerned by
point 1, 2 and 3.
And this should probably be mentionned.
2021-02-05 09:41:51 +00:00
I think we could probably give a few hints.
So in your point 6
> Enter the Redirect URL that the authorization server uses to redirect back to the application.
> Click Add another Redirect URL to enter multiple URLs.
I think you should probably mention that all URL must start with =https://=
and should not contain any =*=.
2021-02-05 09:44:06 +00:00
And for point 7
> Choose the Availability from the drop-down list. You can make the client
> available to User, Organization, or Everyone.
You should probably mention that selecting Everyone is subject to approval
and will need the intervention of a Cisco Administrator to approve your client.
We should probably add a short sentence explaining what is Availbility for.
This is not an OAuth2 standard field.
Availabilty "Org" mean that only member of your own Organization will be
able to approve your client and this should probably be your default choice.
2021-02-05 09:45:36 +00:00
I hope I have been helpful.
Do not hesitate to reach out if you have more questions.
2021-02-08 11:10:26 +00:00
** 2021-W06
*** 2021-02-08 Monday
2021-02-10 09:19:45 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-02-08 Mon 19:45]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+---------------+----------------------------------+--------+---+------+------|
| | | *Total time* | *7:36* | | | |
|------------------------+---------------+----------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-02-08 Monday][2021-02-08 Monday]] | | | 7:36 | |
| [2021-02-08 Mon 17:01] | work, meeting | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*CSA Migration meeting][CSA Migration meeting]] | | | | 2:44 |
| [2021-02-08 Mon 12:08] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Module configuration doc][Module configuration doc]] | | | | 4:52 |
#+END:
2021-03-08 18:01:11 +00:00
**** MEETING CSA Migration meeting :work:meeting:
2021-02-08 16:02:25 +00:00
:LOGBOOK:
2021-02-10 09:19:45 +00:00
CLOCK: [2021-02-08 Mon 17:01]--[2021-02-08 Mon 19:45] => 2:44
2021-02-08 16:02:25 +00:00
:END:
[2021-02-08 Mon 17:01]
- ref ::
2021-02-08 17:34:07 +00:00
Problem with prefixes.
2021-02-08 16:02:25 +00:00
2021-02-08 17:34:07 +00:00
Here is the fix: https://github.com/threatgrid/iroh/pull/4763
2021-03-08 18:01:11 +00:00
**** REVIEW Module configuration doc :work:review:
2021-02-08 11:10:26 +00:00
:LOGBOOK:
2021-02-08 16:02:25 +00:00
CLOCK: [2021-02-08 Mon 12:09]--[2021-02-08 Mon 17:01] => 4:52
2021-02-08 11:10:26 +00:00
:END:
[2021-02-08 Mon 12:08]
- ref :: https://github.com/threatgrid/response/blob/master/features/platform/module_activation.png
2021-02-10 09:19:45 +00:00
*** 2021-02-10 Wednesday
2021-02-10 14:25:25 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
#+CAPTION: Clock summary at [2021-02-10 Wed 15:25]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+--------------+-----------------------------------------+--------+---+------+------|
| | | *Total time* | *3:19* | | | |
|------------------------+--------------+-----------------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-02-10 Wednesday][2021-02-10 Wednesday]] | | | 3:19 | |
| [2021-02-10 Wed 15:23] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Victor PR about build speed-up][Victor PR about build speed-up]] | | | | 1:14 |
| [2021-02-10 Wed 11:01] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*write weekly status][write weekly status]] | | | | 0:34 |
| [2021-02-10 Wed 10:18] | work, chat | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Jyoti CSA Migration, Account Activation Simplification][Jyoti CSA Migration, Account...]] | | | | 1:31 |
#+END:
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS Document SBG single account :work:
2021-02-10 16:07:09 +00:00
:LOGBOOK:
2021-02-11 10:01:17 +00:00
CLOCK: [2021-02-10 Wed 17:06]--[2021-02-10 Wed 18:06] => 1:00
2021-02-10 16:07:09 +00:00
:END:
[2021-02-10 Wed 17:06]
- ref :: [[file:~/dev/iroh/int-modules/amp-investigate/src/amp_investigate/events.clj::(ns amp-investigate.events]]
2021-03-08 18:01:11 +00:00
**** DONE Prepare meeting :work:
2021-02-10 14:27:54 +00:00
:LOGBOOK:
2021-02-10 16:07:09 +00:00
CLOCK: [2021-02-10 Wed 15:26]--[2021-02-10 Wed 17:06] => 1:40
2021-02-10 14:27:54 +00:00
:END:
[2021-02-10 Wed 15:26]
2021-02-10 14:31:40 +00:00
1. How's everyone? Good, Great, Bad, Sad?
2. Short daily stand up.
2021-02-10 14:43:36 +00:00
- Done
- Doing
- need help
2021-03-08 18:01:11 +00:00
**** REVIEW Victor PR about build speed-up :work:review:
2021-02-10 14:25:25 +00:00
:LOGBOOK:
CLOCK: [2021-02-10 Wed 14:10]--[2021-02-10 Wed 15:24] => 1:14
:END:
[2021-02-10 Wed 15:23]
2021-03-08 18:01:11 +00:00
**** DONE write weekly status :work:
2021-02-10 10:02:21 +00:00
:LOGBOOK:
2021-02-10 14:25:25 +00:00
CLOCK: [2021-02-10 Wed 11:01]--[2021-02-10 Wed 11:35] => 0:34
2021-02-10 10:02:21 +00:00
:END:
[2021-02-10 Wed 11:01]
2021-02-10 10:03:26 +00:00
- CSA Migration work:
- Implemented a PoC for plan B (migration via provisioning API)
- Tested the PoC using Vitalii work on AMP team
- Jyoti/QA/AMP Team tests (engineering)
2021-02-10 10:04:49 +00:00
- Propose other improvements (write a long detailed document about
2021-02-10 10:09:06 +00:00
possibilities to help Elias think about what is possible)
2021-02-10 09:20:58 +00:00
**** CHAT Jyoti CSA Migration, Account Activation Simplification :work:chat:
2021-02-10 09:19:45 +00:00
:LOGBOOK:
2021-02-10 14:25:25 +00:00
CLOCK: [2021-02-10 Wed 09:30]--[2021-02-10 Wed 11:01] => 1:31
2021-02-10 09:19:45 +00:00
:END:
[2021-02-10 Wed 10:18]
- ref ::
2021-02-11 10:01:17 +00:00
*** 2021-02-11 Thursday
2021-02-11 10:02:50 +00:00
#+BEGIN: clocktable :scope subtree :maxlevel 4 :timestamp t :link t :tags t :narrow 36! :match "work"
2021-02-11 13:19:04 +00:00
#+CAPTION: Clock summary at [2021-02-11 Thu 14:17]
| Timestamp | Tags | Headline | Time | | | |
|------------------------+--------------+--------------------------------------------+--------+---+------+------|
| | | *Total time* | *2:37* | | | |
|------------------------+--------------+--------------------------------------------+--------+---+------+------|
| | | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-02-11 Thursday][2021-02-11 Thursday]] | | | 2:37 | |
| [2021-02-11 Thu 11:00] | work | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*write doc for Auth/Id improvements][write doc for Auth/Id improvements]] | | | | 1:07 |
| [2021-02-11 Thu 09:10] | work, review | \_ [[file:/Users/esposito/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*multiple reviews and comment][multiple reviews and comment]] | | | | 1:30 |
2021-02-11 10:02:50 +00:00
#+END:
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS write doc for Auth/Id improvements :work:
2021-02-11 10:01:17 +00:00
:LOGBOOK:
2021-02-15 10:21:13 +00:00
CLOCK: [2021-02-11 Thu 14:17]--[2021-02-15 Mon 11:20] => 93:03
2021-02-11 13:19:04 +00:00
CLOCK: [2021-02-11 Thu 11:00]--[2021-02-11 Thu 12:07] => 3:17
2021-02-11 10:01:17 +00:00
:END:
[2021-02-11 Thu 11:00]
2021-03-08 18:01:11 +00:00
**** REVIEW multiple reviews and comment :work:review:
2021-02-11 10:02:50 +00:00
:LOGBOOK:
2021-02-11 13:19:04 +00:00
CLOCK: [2021-02-11 Thu 09:10]--[2021-02-11 Thu 10:40] => 1:30
2021-02-11 10:02:50 +00:00
:END:
[2021-02-11 Thu 09:10]
2021-02-15 10:21:13 +00:00
** 2021-W07
*** 2021-02-15 Monday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS Authentication, ID, Activation Optimisation :work:
2021-02-15 10:21:13 +00:00
:LOGBOOK:
2021-02-16 08:09:10 +00:00
CLOCK: [2021-02-15 Mon 11:20]--[2021-02-16 Tue 09:07] => 21:47
2021-02-15 10:21:13 +00:00
:END:
[2021-02-15 Mon 11:20]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/Cisco.org.gpg::*managed IdP vs non-managed IdP and org-ids][managed IdP vs non-managed IdP and org-ids]]
2021-02-16 08:09:10 +00:00
*** 2021-02-16 Tuesday
2021-03-08 18:01:11 +00:00
**** DONE create OAuth2 clients for Vitalii in PROD :work:
2021-02-16 15:35:58 +00:00
:LOGBOOK:
CLOCK: [2021-02-16 Tue 16:34]--[2021-02-16 Tue 16:35] => 0:01
:END:
[2021-02-16 Tue 16:34]
- ref :: [[file:~/dev/iroh/services/iroh-auth/test/iroh_auth/iroh_auth_web_service_test.clj:::expect-merge? true]]
2021-03-08 18:01:11 +00:00
**** DONE update SSE clients :work:
2021-02-16 14:23:31 +00:00
:LOGBOOK:
2021-02-16 15:35:58 +00:00
CLOCK: [2021-02-16 Tue 15:22]--[2021-02-16 Tue 16:34] => 1:12
2021-02-16 14:23:31 +00:00
:END:
[2021-02-16 Tue 15:22]
- ref :: [[orgit:~/dev/iroh/][~/dev/iroh/ (magit-status)]]
2021-02-16 14:30:46 +00:00
***** NAM
client-id: client-3e55e6a3-4561-4733-b380-ffbd94733ba1
2021-02-16 14:29:44 +00:00
2021-02-16 14:30:46 +00:00
#+begin_src js
{
"scopes": [
"integration",
"private-intel",
"admin",
"profile",
"inspect",
"iroh-master",
"iroh-auth",
"sse",
"users",
"casebook",
"orbital",
"enrich",
"oauth",
"global-intel",
"collect",
"response",
"ui-settings",
"openid",
"ao"
],
"description": "PROD NAM Environment for Security Services Exchange Admin Console",
"approved?": true,
"redirects": [
"https://admin.sse.itd.cisco.com/*/*",
"https://admin.sse.itd.cisco.com/*/*/*",
"https://admin.sse.itd.cisco.com/*",
"https://admin.sse.itd.cisco.com/*/*/*/*",
"https://devops.sse.itd.cisco.com/*/*",
"https://devops.sse.itd.cisco.com/*/*/*",
"https://devops.sse.itd.cisco.com/*",
"https://devops.sse.itd.cisco.com/*/*/*/*"
],
"availability": "everyone",
"access-token-lifetime-in-sec": 86400,
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG",
"idb-amp": "AMP"
},
"default-value": "AMP",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin",
"iroh-admin": "admin"
},
"default-value": "user",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
],
"password": "$s0$f0801$yjznqcXJR2qIloN/JFc4LQ==$FPuIlE/C5Pk/vVG+VVJeTos5UtV5HPhDveM3T/m4wAg=",
"id-token-lifetime-in-sec": 86400,
"name": "sse-ui-prod-nam-client",
"org-id": "576c9ad4-7820-44ca-9d5e-6ca678eadcd1",
"enabled?": true,
"grants": [
"auth-code"
],
"client-type": "confidential",
"id": "client-3e55e6a3-4561-4733-b380-ffbd94733ba1",
"approval-status": "approved",
"owner-id": "d697511a-9164-49d0-8c7b-a5c1a11fb25d",
"created-at": "2020-02-03T13:48:54.758Z"
}
2021-02-16 14:29:44 +00:00
#+end_src
2021-02-16 14:32:04 +00:00
****** PATCH
#+begin_src js
{
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG",
"idb-amp": "AMP"
},
"default-value": "AMP",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG",
"idb-amp": "AMP"
},
"default-value": "AMP",
"claim-to-alias": "old-idp-mapping-idp"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "old-idp-mapping-organization-id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin",
"iroh-admin": "admin"
},
"default-value": "user",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
]
}
#+end_src
2021-02-16 14:35:54 +00:00
***** EU
become master:
user-id: 080c8271-e1c7-4fe6-b6e2-bc1fda123432
2021-02-16 14:39:12 +00:00
done.
#+begin_src js
2021-02-16 14:41:08 +00:00
{
"scopes": [
"integration",
"private-intel",
"admin",
"profile",
"inspect",
"iroh-master",
"iroh-auth",
"sse",
"users",
"casebook",
"orbital",
"enrich",
"oauth",
"global-intel",
"collect",
"response",
"ui-settings",
"openid",
"ao"
],
"description": "PROD EU Environment for Security Services Exchange Admin Console",
"approved?": true,
"redirects": [
"https://admin.eu.sse.itd.cisco.com/*/*",
"https://admin.eu.sse.itd.cisco.com/*/*/*",
"https://admin.eu.sse.itd.cisco.com/*",
"https://admin.eu.sse.itd.cisco.com/*/*/*/*",
"https://devops.eu.sse.itd.cisco.com/*/*",
"https://devops.eu.sse.itd.cisco.com/*/*/*",
"https://devops.eu.sse.itd.cisco.com/*",
"https://devops.eu.sse.itd.cisco.com/*/*/*/*"
],
"availability": "everyone",
"access-token-lifetime-in-sec": 86400,
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG-EU",
"idb-amp": "AMP-EU"
},
"default-value": "AMP-EU",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin",
"iroh-admin": "admin"
},
"default-value": "user",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
],
"password": "$s0$f0801$yjznqcXJR2qIloN/JFc4LQ==$FPuIlE/C5Pk/vVG+VVJeTos5UtV5HPhDveM3T/m4wAg=",
"id-token-lifetime-in-sec": 86400,
"name": "sse-ui-prod-eu-client",
"org-id": "576c9ad4-7820-44ca-9d5e-6ca678eadcd1",
"enabled?": true,
"grants": [
"auth-code"
],
"client-type": "confidential",
"id": "client-3e55e6a3-4561-4733-b380-ffbd94733ba1",
"approval-status": "approved",
"owner-id": "d697511a-9164-49d0-8c7b-a5c1a11fb25d",
"created-at": "2020-02-03T13:48:54.758Z"
}
#+end_src
PATCH
2021-02-16 14:39:12 +00:00
2021-02-16 14:41:08 +00:00
#+begin_src js
{
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG-EU",
"idb-amp": "AMP-EU"
},
"default-value": "AMP-EU",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG-EU",
"idb-amp": "AMP-EU"
},
"default-value": "AMP-EU",
"claim-to-alias": "old-idp-mapping-idp"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "old-idp-mapping-organization-id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin",
"iroh-admin": "admin"
},
"default-value": "user",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
]}
2021-02-16 14:39:12 +00:00
#+end_src
2021-02-16 14:43:14 +00:00
***** APJC
Become master: user-id: b19d5dea-5aa4-4265-b42d-9acc1e913f01
2021-02-16 14:45:41 +00:00
done.
****** Client client-3e55e6a3-4561-4733-b380-ffbd94733ba1
#+begin_src js
2021-02-16 14:47:23 +00:00
{
"scopes": [
"integration",
"private-intel",
"admin",
"profile",
"inspect",
"iroh-master",
"iroh-auth",
"sse",
"users",
"casebook",
"orbital",
"enrich",
"oauth",
"global-intel",
"collect",
"response",
"ui-settings",
"openid",
"ao"
],
"description": "PROD APJC Environment for Security Services Exchange Admin Console",
"approved?": true,
"redirects": [
"https://admin.apj.sse.itd.cisco.com/*/*",
"https://admin.apj.sse.itd.cisco.com/*/*/*",
"https://admin.apj.sse.itd.cisco.com/*",
"https://admin.apj.sse.itd.cisco.com/*/*/*/*",
"https://devops.apj.sse.itd.cisco.com/*/*",
"https://devops.apj.sse.itd.cisco.com/*/*/*",
"https://devops.apj.sse.itd.cisco.com/*",
"https://devops.apj.sse.itd.cisco.com/*/*/*/*",
"https://devops.apj.sse.itd.cisco.com"
],
"availability": "everyone",
"access-token-lifetime-in-sec": 86400,
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG-APJ",
"idb-amp": "AMP-APJ"
},
"default-value": "AMP",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin",
"iroh-admin": "admin"
},
"default-value": "user",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
],
"password": "$s0$f0801$yjznqcXJR2qIloN/JFc4LQ==$FPuIlE/C5Pk/vVG+VVJeTos5UtV5HPhDveM3T/m4wAg=",
"id-token-lifetime-in-sec": 86400,
"name": "sse-ui-prod-apjc-client",
"org-id": "576c9ad4-7820-44ca-9d5e-6ca678eadcd1",
"enabled?": true,
"grants": [
"auth-code"
],
"client-type": "confidential",
"id": "client-3e55e6a3-4561-4733-b380-ffbd94733ba1",
"approval-status": "approved",
"owner-id": "d697511a-9164-49d0-8c7b-a5c1a11fb25d",
"created-at": "2020-02-03T13:48:54.758Z"
}
#+end_src
PATCH
#+begin_src js
{
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG-APJ",
"idb-amp": "AMP-APJ"
},
2021-02-16 18:38:07 +00:00
"default-value": "AMP-APJ",
2021-02-16 14:47:23 +00:00
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG-APJ",
"idb-amp": "AMP-APJ"
},
2021-02-16 18:38:07 +00:00
"default-value": "AMP-APJ",
2021-02-16 14:47:23 +00:00
"claim-to-alias": "old-idp-mapping-idp"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "old-idp-mapping-organization-id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin",
"iroh-admin": "admin"
},
"default-value": "user",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
]
}
2021-02-16 14:45:41 +00:00
2021-02-16 14:48:41 +00:00
#+end_src
****** Client client-92258bc0-196a-4f6c-a0b5-fe105de5f505
#+begin_src js
{
"scopes": [
"integration",
"private-intel",
"admin",
"profile",
"inspect",
"iroh-master",
"iroh-auth",
"sse",
"users",
"casebook",
"orbital",
"enrich",
"oauth",
"global-intel",
"collect",
"response",
"ui-settings",
"openid",
"ao"
],
"description": "PROD APJC Environment for Security Services Exchange Admin Console",
"approved?": true,
"redirects": [
"http://localhost:*/*",
"https://localhost:*/*/*/*",
"https://localhost:*/*/*",
"https://admin.apj.sse.itd.cisco.com/*/*",
"https://admin.apj.sse.itd.cisco.com/*/*/*",
"https://admin.apj.sse.itd.cisco.com/*",
"https://admin.apj.sse.itd.cisco.com/*/*/*/*",
"https://localhost:*",
"http://localhost:*/*/*/*",
"https://localhost:*/*",
"http://localhost:*/*/*",
"http://localhost:*"
],
"availability": "everyone",
"access-token-lifetime-in-sec": 86400,
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"default-value": "AMP",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "companyId",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin"
},
"default-value": "admin",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
],
"password": "$s0$f0801$1oB9uodlfkUpACx2HNnVcQ==$eLNMiORI5R4jCWZp40fGyQvU59bqigGtwoYr8f7cVzU=",
"id-token-lifetime-in-sec": 86400,
"name": "sse-ui-dev-client",
"org-id": "63489cf9-561c-4958-a13d-6d84b7ef09d4",
"enabled?": true,
"grants": [
"auth-code"
],
"client-type": "confidential",
"id": "client-92258bc0-196a-4f6c-a0b5-fe105de5f505",
"approval-status": "approved",
"owner-id": "6ee52ee9-2e3a-4e1b-977d-961facb5fd84",
"created-at": "2020-02-03T13:48:54.758Z"
}
#+end_src
PATCH
#+begin_src js
{ "id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"default-value": "AMP",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"default-value": "AMP",
"claim-to-alias": "old-idp-mapping-idp"
},
{
"alias": "companyId",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
2021-02-16 14:50:01 +00:00
{
"alias": "companyId",
"claim-to-alias": "old-idp-mapping-organization-id"
},
2021-02-16 14:48:41 +00:00
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin"
},
"default-value": "admin",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
]}
2021-02-16 14:45:41 +00:00
#+end_src
2021-03-08 18:01:11 +00:00
**** DONE CSA Migration: merge user by email :work:
2021-02-16 08:09:10 +00:00
:LOGBOOK:
2021-02-16 14:23:31 +00:00
CLOCK: [2021-02-16 Tue 09:07]--[2021-02-16 Tue 15:22] => 6:15
2021-02-16 08:09:10 +00:00
:END:
[2021-02-16 Tue 09:07]
2021-02-17 13:53:43 +00:00
*** 2021-02-17 Wednesday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS clients SSE :work:
2021-02-17 16:26:36 +00:00
:LOGBOOK:
2021-02-18 08:19:48 +00:00
CLOCK: [2021-02-17 Wed 17:25]--[2021-02-18 Thu 09:18] => 15:53
2021-02-17 16:26:36 +00:00
:END:
[2021-02-17 Wed 17:25]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/Cisco.org.gpg::*TEST][TEST]]
2021-03-08 18:01:11 +00:00
**** MEETING weekly meeting :work:meeting:
2021-02-17 15:03:15 +00:00
:LOGBOOK:
2021-02-17 16:26:36 +00:00
CLOCK: [2021-02-17 Wed 16:02]--[2021-02-17 Wed 17:25] => 1:23
2021-02-17 15:03:15 +00:00
:END:
[2021-02-17 Wed 16:02]
- ref ::
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS Update SSE client 2nd pass :work:
2021-02-17 13:53:43 +00:00
:LOGBOOK:
2021-02-17 15:03:15 +00:00
CLOCK: [2021-02-17 Wed 14:52]--[2021-02-17 Wed 16:02] => 1:10
2021-02-17 13:53:43 +00:00
:END:
[2021-02-17 Wed 14:52]
2021-02-18 08:19:48 +00:00
*** 2021-02-18 Thursday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS debug claim aliases :work:
2021-02-18 08:19:48 +00:00
:LOGBOOK:
2021-02-19 14:42:56 +00:00
CLOCK: [2021-02-18 Thu 09:18]--[2021-02-18 Thu 10:38] => 1:20
2021-02-18 08:19:48 +00:00
:END:
[2021-02-18 Thu 09:18]
- ref :: [[file:~/dev/iroh/services/iroh-auth/src/iroh_auth/oauth2_service/schemas.clj::{:claim-to-alias s/Str]]
2021-02-19 14:42:56 +00:00
*** 2021-02-19 Friday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS Device Grant analysis :work:
2021-02-22 15:03:36 +00:00
[2021-02-19 Fri 15:41]
** 2021-W08
*** 2021-02-22 Monday
2021-03-08 18:01:11 +00:00
**** MEETING Core Team: SecureX Account Activation Optimization :work:meeting:
2021-02-19 14:42:56 +00:00
:LOGBOOK:
2021-02-23 07:48:42 +00:00
CLOCK: [2021-02-22 Mon 16:02]--[2021-02-23 Tue 08:47] => 16:45
2021-02-19 14:42:56 +00:00
:END:
2021-02-22 15:03:36 +00:00
[2021-02-22 Mon 16:02]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/inbox.org::*revision chaudiere][revision chaudiere]]
2021-02-22 15:07:30 +00:00
#+begin_quote
Meeting Agenda:
* Discussion to drive forward SecureX Account Activation Optimization Q3 efforts
* Account Creation Workflow
* CSA Migration (has it own dedicated work stream but is there anything impacting the overall initiative?)
* Firepower Onboarding (has it own dedicated work stream but is there anything impacting the overall initiative?)
* Workflow
* Role Based Access
* Module Addition/Health Workflow
* Status of action items from last core team call
* What help is needed (decisions, clarity, etc.)
* Any blockers or issues?
#+end_quote
2021-02-22 15:28:47 +00:00
- http://github.com/threatgrid/response/issues/567
2021-02-22 15:07:30 +00:00
2021-02-22 15:03:36 +00:00
Doing in Q3.
2021-02-22 15:04:43 +00:00
Most conversation is good.
Agenda:
2021-02-22 15:05:52 +00:00
@Jyoti, this is a huge item.
Audience in this meeting is too big.
2021-02-22 15:07:30 +00:00
Where to track.
2021-02-22 15:09:02 +00:00
Some github issue are dead.
Namrata: focus on first 3 items.
2021-02-22 15:10:22 +00:00
Martin: item named workflow, don't know what that is.
2021-02-22 15:28:47 +00:00
Module Addition.
2021-02-23 07:48:42 +00:00
*** 2021-02-23 Tuesday
**** CHAT webex morning routine :work:chat:
:LOGBOOK:
2021-02-24 14:56:22 +00:00
CLOCK: [2021-02-23 Tue 08:47]--[2021-02-23 Tue 09:47] => 1:00
2021-02-23 07:48:42 +00:00
:END:
[2021-02-23 Tue 08:47]
***** CSA Migration
2021-02-23 07:50:01 +00:00
- https://jira-eng-rtp3.cisco.com/jira/browse/VOL-3882
2021-03-02 15:02:43 +00:00
***** DONE Houman
2021-02-23 08:09:53 +00:00
SCHEDULED: <2021-02-23 Tue 16:00>
2021-02-23 07:59:10 +00:00
2021-02-23 08:21:44 +00:00
@Houman
2021-02-23 07:59:10 +00:00
Hi Yann - something for tomorrow, none of the QA orgs in TEST or INT are
showing the registered devices in SSE.
When I cross launch to SSE, I am able to see the devices, but in SecureX
there is no device.
Both are AMP orgs and already migrated.
Here are the org IDs:
#+begin_src
c395f3c8-723b-4d15-b8b7-e17bec459c6b
cc6a35bc-1739-4fcd-a285-aa95adbd5e41
#+end_src
Could you please take a look and unblock QA orgs?
2021-02-23 08:21:44 +00:00
****** Investigation
2021-02-23 08:23:14 +00:00
INT org
2021-02-23 08:21:44 +00:00
#+begin_src js
{
"id": "c395f3c8-723b-4d15-b8b7-e17bec459c6b",
"name": "adminctrqa",
"enabled?": true,
"created-at": "2019-04-04T20:33:53.033Z",
"idp-mapping": {
"idp": "idb-amp-staging",
"enabled?": true,
"organization-id": "c395f3c8-723b-4d15-b8b7-e17bec459c6b"
},
"scim-status": "activated",
"additional-scopes": [
"iroh-admin",
"iroh-master",
"iroh-auth",
"sse",
"cisco"
]
}
#+end_src
2021-02-23 08:23:14 +00:00
Contains =idp-mapping=.
Logs during OIDC does not contain it:
2021-02-23 08:24:40 +00:00
The client claim-aliases looks ok:
2021-02-23 08:23:14 +00:00
2021-02-23 08:24:40 +00:00
#+begin_src
"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"claim-to-alias": "idp-mapping-idp"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"claim-to-alias": "old-idp-mapping-idp"
},
2021-02-23 08:23:14 +00:00
#+end_src
2021-02-24 14:56:22 +00:00
*** 2021-02-24 Wednesday
2021-03-08 18:01:11 +00:00
**** MEETING Fix SSE client :work:meeting:
2021-02-24 17:35:20 +00:00
:LOGBOOK:
2021-02-25 17:08:49 +00:00
CLOCK: [2021-02-24 Wed 18:33]--[2021-02-25 Thu 18:07] => 23:34
2021-02-24 17:35:20 +00:00
:END:
[2021-02-24 Wed 18:33]
client PATCH
TEST:
#+begin_src js
{"id-token-aliases": [
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG",
"threatgrid":"TG",
"idb-amp": "AMP",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"default-value": "AMP",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/idp/id"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG",
"threatgrid":"TG",
"idb-amp": "AMP",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"claim-to-alias": "idp-mapping-idp"
},
{
"alias": "spId",
"case-value": {
"sxso": "SXSO",
"idb-tg": "TG",
"threatgrid":"TG",
"idb-amp": "AMP",
"idb-tg-staging": "TG",
"idb-amp-staging": "AMP"
},
"claim-to-alias": "old-idp-mapping-idp"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "idp-mapping-organization-id"
},
{
"alias": "companyId",
"replace-value": [
[
"^threatgrid[:]",
""
]
],
"claim-to-alias": "old-idp-mapping-organization-id"
},
{
"alias": "companyName",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/org/name"
},
{
"alias": "user_name",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/name"
},
{
"alias": "user_email",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/email"
},
{
"alias": "role",
"case-value": {
"admin": "admin",
"master": "admin",
"iroh-admin": "admin"
},
"default-value": "user",
"claim-to-alias": "https://schemas.cisco.com/iroh/identity/claims/user/role"
}
]}
#+end_src
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS continue the day :work:
2021-02-24 16:05:31 +00:00
:LOGBOOK:
2021-02-24 17:35:20 +00:00
CLOCK: [2021-02-24 Wed 17:04]--[2021-02-24 Wed 18:33] => 1:29
2021-02-24 16:05:31 +00:00
:END:
[2021-02-24 Wed 17:04]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Notes][Notes]]
2021-03-08 18:01:11 +00:00
**** MEETING dev weekly :work:meeting:
2021-02-24 14:56:22 +00:00
:LOGBOOK:
2021-02-24 16:05:31 +00:00
CLOCK: [2021-02-24 Wed 15:55]--[2021-02-24 Wed 17:04] => 1:09
2021-02-24 14:56:22 +00:00
:END:
[2021-02-24 Wed 15:55]
2021-02-24 15:01:52 +00:00
***** Weekly status
****** commits
2021-02-24 14:57:37 +00:00
IROH:
- Provisioning: organization-id added to idp-mapping (#4855)
- Use entities in DB during SSE id-token generation (#4844) …
- Added tests to verify #4808 (#4817) …
- Hide provisioning API routes (#4835)
- OAuth2 client availabilty restriction for non admin (#4820) …
- Prevent user merge by email for some IdP (#4819) …
Tenzin-config:
Provisioning API in PROD (#375)
Mark some IdP as safe for email (#374)
2021-02-24 15:01:52 +00:00
****** Reviews
2021-02-24 14:59:16 +00:00
- Extract `user->identity` helper
- RFC Problem Statement: Managing transitive dependencies for "test" jars
- Add schema validation for `gen-jwt`
- Use EmailService in iroh-feedback
- RFC: Prevent dependency confusion attack on our code base
- Add a `svc-helper` for `iroh-int.test-helpers.auth`
2021-02-24 15:01:52 +00:00
****** Issues
2021-02-24 15:00:28 +00:00
2021-02-24 15:01:52 +00:00
- [ ] Write tests for #4844
- [ ] Update SSE Clients
2021-02-24 15:00:28 +00:00
- [X] SSE wrong org object passed to id_token generation
- [X] Prevent merge user by email for TG accounts
- [X] Claim aliases bug fix
- [X] Prevent non-admin users to create client with availability "Org"
2021-02-24 15:03:24 +00:00
****** Webex
2021-02-24 15:33:30 +00:00
***** Notes
2021-02-24 15:38:14 +00:00
- Yann:
+ CSA Migration, Talk about SSE, and release.
- Guillaume:
+ CSA Migration
+ Status API route
+ FMC
2021-02-24 15:36:41 +00:00
- Rob:
+ discussion about Ben Greenbaum and Umbrella module (409 hit)
2021-02-24 15:40:11 +00:00
- Ag:
+ Bundle assets
2021-02-24 15:43:15 +00:00
- Ambrose:
+ Fixed the cron-job
+ finished email service
+ research work about problem statement
2021-02-24 16:05:31 +00:00
Real Work™ discussion.
2021-03-02 15:02:43 +00:00
** 2021-W09
*** 2021-03-02 Tuesday
2021-03-08 18:01:11 +00:00
**** MEETING Account Activation Optimization :work:meeting:
2021-03-02 15:02:43 +00:00
:LOGBOOK:
2021-03-03 17:38:34 +00:00
CLOCK: [2021-03-02 Tue 16:01]--[2021-03-02 Tue 17:21] => 1:20
2021-03-02 15:02:43 +00:00
:END:
[2021-03-02 Tue 16:01]
- ref :: [[file:~/dev/iroh/lib/log-helper/src/log_helper/testutils.clj][file:~/dev/iroh/lib/log-helper/src/log_helper/testutils.clj]]
2021-03-02 15:05:57 +00:00
Centralize tools from different groups.
One stop shop.
2021-03-02 15:09:32 +00:00
Account Activation/Firepower.
Epics/issues.
2021-03-02 15:27:24 +00:00
https://github.com/threatgrid/response/issues/577
https://github.com/threatgrid/response/issues/565
https://github.com/threatgrid/response/issues/562
2021-03-03 17:38:34 +00:00
*** 2021-03-03 Wednesday
2021-03-08 18:01:11 +00:00
**** MEETING PosaaS :work:meeting:
2021-03-03 17:38:34 +00:00
:LOGBOOK:
2021-03-04 09:15:31 +00:00
CLOCK: [2021-03-03 Wed 18:37]--[2021-03-03 Wed 19:45] => 1:08
2021-03-03 17:38:34 +00:00
:END:
[2021-03-03 Wed 18:37]
2021-03-03 17:44:50 +00:00
Posaas: Posture as a Service
2021-03-03 17:49:43 +00:00
2021-03-03 17:51:38 +00:00
- Actionable items
- cross launch
2021-03-04 09:26:32 +00:00
*** 2021-03-04 Thursday
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS NGFW improvements :work:
2021-03-04 09:26:32 +00:00
:LOGBOOK:
2021-03-08 18:01:11 +00:00
CLOCK: [2021-03-04 Thu 10:25]--[2021-03-05 Fri 20:36] => 34:11
2021-03-04 09:26:32 +00:00
:END:
[2021-03-04 Thu 10:25]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Account Activation Optimization][Account Activation Optimization]]
2021-03-08 18:01:11 +00:00
**** IN-PROGRESS discussions TD :work:
2021-03-04 09:26:32 +00:00
:LOGBOOK:
CLOCK: [2021-03-04 Thu 10:25]--[2021-03-04 Thu 10:25] => 0:00
:END:
[2021-03-04 Thu 07:25]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*Account Activation Optimization][Account Activation Optimization]]
2021-03-08 18:01:11 +00:00
** 2021-W10
*** 2021-03-08 Monday
2021-05-03 06:20:18 +00:00
**** MEETING IROH Token & Posture :work:meeting:
2021-03-08 18:01:11 +00:00
:LOGBOOK:
2021-03-09 05:06:14 +00:00
CLOCK: [2021-03-08 Mon 19:00]--[2021-03-08 Mon 20:32] => 1:32
2021-03-08 18:01:11 +00:00
:END:
[2021-03-08 Mon 18:59]
2021-03-08 18:04:01 +00:00
Experience we're trying to reach with Posture.
2021-03-08 18:05:41 +00:00
Martin should feel like a Platform.
Selectively select product.
Onboard AMP only once for everything.
2021-03-08 18:09:13 +00:00
J: Posture should abide IROH-Auth OIDC to prevent discrepencies
2021-03-08 18:10:40 +00:00
2021-03-08 18:09:13 +00:00
Didi: I would like to separate that.
2021-03-08 18:10:40 +00:00
@Didi:
3 types of UX.
1. New user and want to start SecureX. Onboard all modules.
2. I am existing user, I have all enabled. I want to turn on Postule and
modules inside the suite right now.
3. I want to be able to kill my Posture collection. I want to revoke
access.
2021-03-08 18:12:00 +00:00
4. Monitor the situation of what is happening in my system.
2021-03-08 18:13:28 +00:00
Elias:
2021-03-08 18:28:52 +00:00
- org managing.
We're not gonna have Posture to have a separate org management.
Didi:
Back from session.
2021-03-08 18:30:26 +00:00
Hacks Millards
IROH-Auth is the authorize source of orgs.
Basically session manager able to get identity token.
Some org-hint in Okta.
2021-03-08 18:32:26 +00:00
How to integrate Posture in SecureX.
2021-03-08 18:50:20 +00:00
Elias:
2021-03-08 18:51:37 +00:00
Real concern is about webhook integration.
2021-03-09 05:06:14 +00:00
*** 2021-03-09 Tuesday
2021-05-03 06:20:18 +00:00
**** MEETING CSA Migration check :work:meeting:
2021-03-09 05:06:14 +00:00
:LOGBOOK:
2021-03-10 14:24:07 +00:00
CLOCK: [2021-03-09 Tue 06:05]--[2021-03-09 Tue 07:05] => 1:00
2021-03-09 05:06:14 +00:00
:END:
[2021-03-09 Tue 06:04]
- ref ::
2021-03-10 14:24:07 +00:00
*** 2021-03-10 Wednesday
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS weekly :work:
2021-03-10 14:24:07 +00:00
:LOGBOOK:
2021-03-11 17:12:57 +00:00
CLOCK: [2021-03-10 Wed 15:23]--[2021-03-10 Wed 17:07] => 1:44
2021-03-10 14:24:07 +00:00
:END:
[2021-03-10 Wed 15:22]
2021-03-10 14:31:52 +00:00
***** Done
****** CSA Migration
2021-03-10 14:26:45 +00:00
2021-03-10 14:34:24 +00:00
**Meetings**:
2021-03-10 14:30:48 +00:00
2021-03-10 14:31:52 +00:00
- bug fixing due to provisioning API call in PROD
2021-03-10 14:33:04 +00:00
- fix the bug in v1.67; disable provisioning API.
- prevent the provisioning API de delete idp-mappings
2021-03-10 14:30:48 +00:00
- generic discusion about the goals for the Auth for SecureX
2021-03-10 14:34:24 +00:00
- discussion about moving the org/user management to Okta (I think).
2021-03-10 14:30:48 +00:00
2021-03-10 14:34:24 +00:00
**Code**:
2021-03-10 14:30:48 +00:00
2021-03-10 14:27:45 +00:00
- Prevent duplicate user creation via the provisioning API (#4930)
- Improve idp-filter message. (#4921)
- Display Org's idp in account selection (#4909)
- provisioning API further protections (#4919)
- Prevent destructive change via Provisioning API (#4900)
2021-03-10 15:29:22 +00:00
****** Account Activation Optimization
- Relax scopes for non activated accounts (#4891)
2021-03-10 14:31:52 +00:00
****** Tooling
2021-03-10 14:29:13 +00:00
- Easy fix for a faster test (#4936)
- Delete obsolete files. (#4907)
2021-03-10 14:27:45 +00:00
- Destroy tokyo (#4880)
2021-03-10 14:31:52 +00:00
****** Bug fixes
2021-03-10 14:29:13 +00:00
2021-03-10 14:27:45 +00:00
- Fix reported status due to missing scope. (#4886)
2021-03-10 14:35:57 +00:00
***** Working
2021-03-10 14:40:33 +00:00
- Improve Selection Page https://github.com/threatgrid/iroh/issues/4918
- IROH-Auth Session: https://github.com/threatgrid/iroh/issues/4323
- Add/delete cookies during Authentication workflow; https://github.com/threatgrid/iroh/issues/4911
2021-03-10 15:23:17 +00:00
- Checking diff between =uberjar= profile and =test= dependencies version
2021-03-11 17:12:57 +00:00
*** 2021-03-11 Thursday
2021-05-03 06:20:18 +00:00
**** MEETING weekly with Al! :work:meeting:
2021-03-11 17:12:57 +00:00
:LOGBOOK:
2021-03-16 17:30:39 +00:00
CLOCK: [2021-03-11 Thu 18:11]--[2021-03-11 Thu 19:06] => 0:55
2021-03-11 17:12:57 +00:00
:END:
[2021-03-11 Thu 18:11]
2021-03-11 17:15:50 +00:00
CSA migration stress
Al
It works very very well.
It sells more products.
Push the hole portofolio.
Hard for people to enter into the system.
It because more complex.
2021-03-11 17:17:03 +00:00
CSA Migration should be fixed.
Firewall migration is important.
2021-03-11 17:18:36 +00:00
Production issues.
Pressure on the system.
Dates comes from you.
2021-03-11 17:35:43 +00:00
***** Ops
***** Release report from Houman
2021-03-11 18:03:41 +00:00
***** Demos
2021-03-16 17:30:39 +00:00
** 2021-W11
*** 2021-03-16 Tuesday
2021-05-03 06:20:18 +00:00
**** MEETING DUO QA :work:meeting:
2021-03-16 17:30:39 +00:00
:LOGBOOK:
2021-03-25 15:04:43 +00:00
CLOCK: [2021-03-16 Tue 18:29]--[2021-03-16 Tue 19:23] => 0:54
2021-03-16 17:30:39 +00:00
:END:
[2021-03-16 Tue 18:29]
- ref :: [[file:~/dev/iroh/services/iroh-auth/src/iroh_auth/iroh_auth_service/account_selection.clj::\[:span.org-idp (hiccup/h (org-created-via-idp idps account))\]\]]]
2021-03-16 17:32:11 +00:00
2021-03-16 17:35:17 +00:00
Automation with Environment.
2021-03-16 17:32:11 +00:00
2021-03-16 17:35:17 +00:00
What to do and what not to do.
2021-03-16 17:32:11 +00:00
2021-03-16 17:35:17 +00:00
Recap your position Didi.
2021-03-16 17:32:11 +00:00
2021-03-16 17:35:17 +00:00
@Didi:
2021-03-16 17:32:11 +00:00
2021-03-16 17:35:17 +00:00
think outside of the box.
Our concerns from the other side.
Houman conversation.
Single Sign On is tested in a specific way.
We have CI environment.
Display the profile page and display the dashboard that replace the Okta
dashboard.
And provide Okta services.
Template for email and UI.
And rather not have touching these things in production.
So our dev go in the CI env.
Flow user creation, webhooks, etc...
That env is different than previous env.
If you need a CI env.
We recommend people to have their own Okta instance.
Can have as many Okta instances as we want.
2 instances:
- okta preview meant for developers and code integration.
2021-03-16 17:36:22 +00:00
IDE with that. CI, Preview, don't use CDN.
Willing to accept pen testing, etc...
- staging production environment.
2021-03-16 17:38:13 +00:00
Preview env, is stable at code level.
There is a level of testing between okta preview and prod.
2021-03-16 17:39:36 +00:00
3 options of testing.
2021-03-16 17:40:53 +00:00
1. Manually
2. Set of existing users, we give you a DUO bypass code.
We need MFA otherwise fake users creation.
3. Provide MFA in a self-hosted Okta instance.
2021-03-16 17:41:54 +00:00
Personal MFA to be automated.
We plan on enabled Google and not just DUO.
2021-03-16 17:43:52 +00:00
@Houman
Google would help because we could bypass the MFA section.
That would be enough for the automatisation part.
2021-03-16 17:45:04 +00:00
We can create/delete users automatically.
If Google Auth is not a reason.
Our concern is not the number of users.
We cannot have an env without MFA.
2021-03-25 15:04:43 +00:00
** 2021-W12
*** 2021-03-24 Wednesday
2021-05-03 06:20:18 +00:00
**** MEETING Demo CSA Migration :work:meeting:
2021-03-25 15:04:43 +00:00
:LOGBOOK:
CLOCK: [2021-03-24 Wed 15:29]--[2021-03-24 Wed 16:49] => 1:20
:END:
[2021-03-24 Wed 15:29]
***** Andy
Goal:
- Resolving Problems and Plan to our Beta
i
***** Demo April Luk
****** Demo 1
1. Login through CSA
2. Click on Migrate Later
3. Login into SecureX, in Manage Users see use CSA
4. Logout
5. Login through CSA
6. Migrate => Test Login
7. Create a SecureX Account
8. Wait for email, click on the link, activate the account
9. Make the DUO danse
10. Click on Finish (in SXSO after DUO) end up in "Migrate Later" /
"Migrate Now"
11. Error to SXSO idp-filter, link goes to CTR, need to Logout, and back to SecureX
****** Demo 2
1 -> 9 idem
Ping April Luk
Send a demo video
Open issues on the conference page.
SSO conf, beta blocker page.
*** 2021-03-25 Thursday
2021-05-03 06:20:18 +00:00
**** MEETING weekly meeting :work:meeting:
2021-03-25 15:04:43 +00:00
:LOGBOOK:
2021-03-29 18:29:47 +00:00
CLOCK: [2021-03-25 Thu 16:03]--[2021-03-25 Thu 17:23] => 1:20
2021-03-25 15:04:43 +00:00
:END:
[2021-03-25 Thu 16:03]
2021-03-29 18:29:47 +00:00
** 2021-W13
*** 2021-03-29 Monday
2021-05-03 06:20:18 +00:00
**** MEETING Meeting Talk about SSE tokens :work:meeting:
2021-03-29 18:29:47 +00:00
:LOGBOOK:
2021-03-30 08:12:02 +00:00
CLOCK: [2021-03-29 Mon 20:28]--[2021-03-29 Mon 22:49] => 2:21
2021-03-29 18:29:47 +00:00
:END:
[2021-03-29 Mon 20:28]
2021-03-29 18:32:20 +00:00
Cold weather at Didi's place.
2021-03-29 18:33:49 +00:00
Doron: CDO
Doing things with SSE and SecureX.
Device Manager, OIDC.
We look at the user, tenant in SSE, etc...
2021-03-29 18:35:10 +00:00
The flow sometimes break, etc...
Sometimes in the CDO part.
2021-03-29 18:36:34 +00:00
SSE guys told me I need to talk to you to change the flow.
2021-03-30 08:12:02 +00:00
*** 2021-03-30 Tuesday
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS Learn about sessions between different domains :work:
2021-03-30 08:12:02 +00:00
:LOGBOOK:
2021-04-02 13:51:18 +00:00
CLOCK: [2021-03-30 Tue 10:10]--[2021-04-01 Thu 11:30] => 49:20
2021-03-30 08:12:02 +00:00
:END:
[2021-03-30 Tue 10:10]
2021-04-02 13:51:18 +00:00
*** 2021-04-02 Friday
2021-05-03 06:20:18 +00:00
**** MEETING CSA Meeting :work:meeting:
2021-04-08 15:14:20 +00:00
:LOGBOOK:
CLOCK: [2021-04-02 Fri 16:30]--[2021-04-02 Fri 17:50] => 1:20
:END:
[2021-04-02 Fri 16:30]
- ref :: [[file:~/.doom.d/config.el::(<= 10 hour 16) 'doom-oceanic-next]]
Notice form my last update.
Most issue marked as resolved.
Andy:
2021-05-03 06:20:18 +00:00
**** DONE response explanation about Clients :work:
2021-04-02 13:51:18 +00:00
:LOGBOOK:
2021-04-02 13:59:06 +00:00
CLOCK: [2021-04-02 Fri 15:50]--[2021-04-02 Fri 15:58] => 0:08
2021-04-02 13:51:18 +00:00
:END:
[2021-04-02 Fri 15:50]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/Cisco.org.gpg::*Update SSE Clients][Update SSE Clients]]
The most important. Our Client model is not public like it is with Github. So Clients of IROH-Auth are not public by default like this is the case for Github. Every OAuth2 Auth Code client that would like to be used by people outside the org of its owner MUST ask for an approval from a SecureX Administrator.
More precisely:
2021-04-02 14:01:27 +00:00
1. No client can be created that could be used outside of the org without a
Cisco SecureX administrator manually approving that client.
So nobody from any org X could create a client with a fake Application name
and use it outside of their own Org.
Also the client would be updated, it would still need another approval from
us.
2. No client can have the auto-approval feature which is extremely restricted
to only a bunch of trusted clients.
The list of client with auto-approval is put in a separate table only
accessible via Cisco SecureX administrators (us).
2. A lot of existing clients were created before we had the current Data User
structure.
So for example, the Organization name will probably be something no
meaningful.
3. Also many other teams inside Cisco did not create the client themselves and
we created the client for them and we handled them the client credentials.
So would we add the Org name to this page it would mean that we need a lot
of administrative work on the 5 deployed environments to change the owner
of many clients manually.
4. The SecureX/CTR Orgs are not public, they do not have a public profile any
user could check.
We could at most give the name of the org.
I think at most we could show a few data about the Client's owner.
For example it's user name, (email ?), etc...
So unlike with github we cannot give a link to an Org profile webpage.
5. Orgs do not have avatars.
2021-04-08 15:14:20 +00:00
** 2021-W14
*** 2021-04-06 Tuesday
*** 2021-04-08 Thursday
2021-05-03 06:20:18 +00:00
**** MEETING weekly :work:meeting:
2021-04-08 16:37:30 +00:00
:LOGBOOK:
2021-04-09 08:56:38 +00:00
CLOCK: [2021-04-08 Thu 18:10]--[2021-04-08 Thu 19:30] => 1:20
2021-04-08 16:37:30 +00:00
:END:
[2021-04-08 Thu 18:36]
2021-05-03 06:20:18 +00:00
**** MEETING Weekly services meeting :work:meeting:
2021-04-08 16:37:30 +00:00
:LOGBOOK:
CLOCK: [2021-04-08 Thu 17:00]--[2021-04-08 Thu 17:53] => 0:53
:END:
[2021-04-08 Thu 17:13]
- ref ::
**** DONE Check security open issues
2021-04-08 15:14:20 +00:00
***** Markdown security related:
close https://github.com/threatgrid/iroh/issues/2921
close https://github.com/threatgrid/iroh/issues/3399
close https://github.com/threatgrid/iroh/issues/3377
***** Deprecarted/Don't care/Probably fixed/Not a bug, it's a feature
probably fixed: https://github.com/threatgrid/iroh/issues/4277
close https://github.com/threatgrid/iroh/issues/4276
close https://github.com/threatgrid/iroh/issues/4278
close https://github.com/threatgrid/iroh/issues/4507
***** Possible break/surprising UX/etc...
Potentially break dev/integration with other teams due to improved security:
discuss with Orbital about https://github.com/threatgrid/iroh/issues/5121
discuss with SWC about https://github.com/threatgrid/iroh/issues/4387
For v1.71:
Merge https://github.com/threatgrid/iroh/pull/4947
Merge https://github.com/threatgrid/iroh/pull/5106
***** Need design work
https://github.com/threatgrid/iroh/issues/4507
2021-04-09 08:56:38 +00:00
*** 2021-04-09 Friday
2021-05-03 06:20:18 +00:00
**** EMAIL work email tour :work:email:
2021-04-09 09:29:18 +00:00
:LOGBOOK:
2021-04-12 14:30:15 +00:00
CLOCK: [2021-04-09 Fri 11:28]--[2021-04-09 Fri 17:31] => 6:03
2021-04-09 09:29:18 +00:00
:END:
[2021-04-09 Fri 11:28]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/inbox.org::*Ecrire projet de vie][Ecrire projet de vie]]
2021-05-03 06:20:18 +00:00
**** REVIEW Morning gh routine :work:review:
2021-04-09 08:56:38 +00:00
:LOGBOOK:
2021-04-09 09:29:18 +00:00
CLOCK: [2021-04-09 Fri 10:55]--[2021-04-09 Fri 11:28] => 0:33
2021-04-09 08:56:38 +00:00
:END:
[2021-04-09 Fri 10:55]
:refer \[can-create? can-delete? can-read? can-write?\]\]]]
**** CHAT chat tour :work:chat:
:LOGBOOK:
CLOCK: [2021-04-09 Fri 10:05]--[2021-04-09 Fri 10:55] => 0:50
:END:
[2021-04-09 Fri 10:55]
2021-04-12 14:30:15 +00:00
** 2021-W15
*** 2021-04-12 Monday
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS IROH-Auth Session :work:
2021-04-12 14:30:15 +00:00
:LOGBOOK:
2021-04-14 07:22:02 +00:00
CLOCK: [2021-04-12 Mon 16:29]--[2021-04-12 Mon 17:29] => 1:00
2021-04-12 14:30:15 +00:00
:END:
[2021-04-12 Mon 16:28]
- ref :: https://blog.theodo.com/2016/10/how-to-track-your-users-over-several-domains/
2021-04-12 14:31:35 +00:00
- ref :: https://stackoverflow.com/questions/3342140/cross-domain-cookies
2021-04-12 14:34:47 +00:00
- ref :: https://stackoverflow.com/questions/19531183/set-cookie-on-multiple-domains-with-php-or-javascript/19546680#19546680
2021-04-12 14:38:54 +00:00
Seems clear that whatever solution, cross-domain cookies will be more and
more difficult to work as browser vendor will make their best to prevent
user tracking.
So the best solution would be to keep a IROH-Auth local session.
2021-04-12 14:40:19 +00:00
If a user come on the IROH-Auth login page.
We could have put a set of cookies (if we want cross domain but intra
security.cisco.com one) or use localStorage.
1. We should ensure that once the user is logged sucessfully we save the JWT
2021-04-14 07:22:02 +00:00
*** 2021-04-14 Wednesday
2021-05-03 06:20:18 +00:00
**** MEETING interview :work:meeting:
2021-04-14 16:29:48 +00:00
:LOGBOOK:
2021-04-15 08:37:52 +00:00
CLOCK: [2021-04-14 Wed 18:28]--[2021-04-15 Thu 10:36] => 16:08
2021-04-14 16:29:48 +00:00
:END:
[2021-04-14 Wed 18:28]
- ref :: [[file:~/dev/iroh-admin-ui/assets/l33t.css::text-align: left;]]
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS Presentation IROH-Auth :work:
2021-04-14 07:22:02 +00:00
:LOGBOOK:
2021-04-14 16:29:48 +00:00
CLOCK: [2021-04-14 Wed 09:20]--[2021-04-14 Wed 18:28] => 9:08
2021-04-14 07:22:02 +00:00
:END:
[2021-04-14 Wed 09:20]
***** History
2021-04-14 07:26:45 +00:00
1. Login using AMP SAML (generate JWT)
2021-04-14 07:23:20 +00:00
2. OAuth2 Provider (Grants)
3. Login using OpenID Connect with TG (client of OpenID Connect)
2021-04-14 07:25:08 +00:00
4. Users/Orgs in DB!!!
5. Account Activation
6. Become an OpenID Connect provider
7. OIDC with SSE
***** Internal User Structure
2021-04-14 07:26:45 +00:00
***** Cisco specificity
2021-04-15 08:37:52 +00:00
*** 2021-04-15 Thursday
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS presentation IROH-Auth :work:
2021-04-15 08:37:52 +00:00
:LOGBOOK:
2021-04-16 09:57:36 +00:00
CLOCK: [2021-04-15 Thu 10:36]--[2021-04-15 Thu 11:06] => 0:30
2021-04-15 08:37:52 +00:00
:END:
[2021-04-15 Thu 10:36]
2021-04-16 09:57:36 +00:00
*** 2021-04-16 Friday
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS Presentation :work:
2021-04-16 09:57:36 +00:00
:LOGBOOK:
2021-04-23 15:20:52 +00:00
CLOCK: [2021-04-16 Fri 11:56]--[2021-04-16 Fri 12:56] => 1:00
2021-04-16 09:57:36 +00:00
:END:
[2021-04-16 Fri 11:56]
2021-04-23 15:20:52 +00:00
** 2021-W16
*** 2021-04-23 Friday
2021-05-03 06:20:18 +00:00
**** MEETING SSE device + smart accounts :work:meeting:
2021-04-23 15:20:52 +00:00
:LOGBOOK:
2021-04-26 08:04:25 +00:00
CLOCK: [2021-04-23 Fri 17:19]--[2021-04-23 Fri 18:23] => 1:04
2021-04-23 15:20:52 +00:00
:END:
[2021-04-23 Fri 17:19]
:
2021-04-26 08:04:25 +00:00
** 2021-W17
*** 2021-04-26 Monday
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS Device Flow :work:
2021-04-26 08:41:19 +00:00
:LOGBOOK:
2021-04-30 17:07:04 +00:00
CLOCK: [2021-04-26 Mon 10:40]--[2021-04-26 Mon 12:00] => 1:20
2021-04-26 08:41:19 +00:00
:END:
[2021-04-26 Mon 10:40]
- ref ::
2021-04-26 08:04:25 +00:00
**** CHAT Yana redirects :work:chat:
:LOGBOOK:
2021-04-26 08:07:35 +00:00
CLOCK: [2021-04-26 Mon 10:03]--[2021-04-26 Mon 10:06] => 0:03
2021-04-26 08:04:25 +00:00
:END:
[2021-04-26 Mon 10:03]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-04-26 Monday][2021-04-26 Monday]]
2021-04-30 17:07:04 +00:00
*** 2021-04-30 Friday
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS Cognitive :work:
2021-04-30 17:07:04 +00:00
:LOGBOOK:
2021-05-03 06:20:18 +00:00
CLOCK: [2021-04-30 Fri 19:06]--[2021-05-02 Sun 08:10] => 37:04
2021-04-30 17:07:04 +00:00
:END:
[2021-04-30 Fri 19:05]
- ref :: [[file:~/dev/iroh/services/iroh-auth/src/iroh_auth/provisioning/routes.clj:::return \[PlatformUser\]]]
Clients
NAM: client-cd34f85d-1c5f-4e93-856c-4cd7c07b847d
EU: client-c24bcbe6-ea0b-49cd-9aa8-6e7b3b744412
APJC: client-72111422-86be-4a0e-a5ce-0a25e55304a2
Request for new org name:
Global Threat Alerts Integrations - NAM
Global Threat Alerts Integrations - EU
Global Threat Alerts Integrations - APJC
Users
mistanke@cisco.com
mvelk@cisco.com
jpradac@cisco.com
pjisl@cisco.com
mafanta@cisco.com
bdimitri@cisco.com
dastrupl@cisco.com
2021-04-30 17:14:01 +00:00
PATCH:
#+begin_src js
{"org-id": "827f573c-1c08-44a6-9d08-4b8ae03a50a0",
"owner-id": "25de35b8-3069-4e5c-a1b4-506cfb82b6d5"}
#+end_src
2021-04-30 17:08:43 +00:00
***** NAM
2021-04-30 17:14:01 +00:00
client: client-cd34f85d-1c5f-4e93-856c-4cd7c07b847d
2021-04-30 17:08:43 +00:00
User Martin Fanta
2021-04-30 17:20:13 +00:00
user-id: 25de35b8-3069-4e5c-a1b4-506cfb82b6d5
2021-04-30 17:16:25 +00:00
#+begin_src js
{
"role": "admin",
"scopes": [
"vault/configs:read",
"integration",
"private-intel",
"admin",
"profile",
"inspect",
"feedback",
"sse",
"registry",
"users",
"invite",
"casebook",
"vault/config/metadata:read",
"orbital",
"enrich",
"oauth",
"collect",
"response",
"ui-settings",
"telemetry:write",
"openid",
"notification",
"global-intel:read",
"webhook",
"vault/config/posture:read",
"ao"
],
"updated-at": "2021-04-30T14:46:57.763Z",
"idp-mappings": [
{
"idp": "sxso",
"enabled?": true,
"user-identity-id": "00u4ti78a4BXlZSFQ357"
}
],
"user-email": "mafanta@cisco.com",
"user-name": "Martin Fanta",
"org-id": "827f573c-1c08-44a6-9d08-4b8ae03a50a0",
"user-id": "25de35b8-3069-4e5c-a1b4-506cfb82b6d5",
"enabled?": true,
"last-logged-at": [
"2021-04-30T14:47:33.023Z",
"2021-04-30T14:47:14.157Z",
"2021-04-30T14:47:00.478Z",
"2021-04-13T13:48:03.320Z",
"2021-03-18T13:14:51.114Z"
],
"created-at": "2021-03-18T13:14:24.604Z",
"user-nick": "Martin Fanta"
}
#+end_src
Org: =827f573c-1c08-44a6-9d08-4b8ae03a50a0=
#+begin_src js
{
"id": "827f573c-1c08-44a6-9d08-4b8ae03a50a0",
"name": "Global Threat Alerts Integrations - NAM",
"address": {
"city": "",
"street1": "",
"street2": "",
"department": "",
"postal-code": "",
"country-iso-code": "CZ"
},
"enabled?": true,
"created-at": "2021-03-18T13:14:24.597Z",
"scim-status": "activated"
}
#+end_src
***** EU
client: client-c24bcbe6-ea0b-49cd-9aa8-6e7b3b744412
User Martin Fanta
2021-04-30 17:20:13 +00:00
user-id: 25de35b8-3069-4e5c-a1b4-506cfb82b6d5
2021-04-30 17:10:36 +00:00
#+begin_src js
2021-04-30 17:08:43 +00:00
{
"role": "admin",
"scopes": [
"vault/configs:read",
"integration",
"private-intel",
"admin",
"profile",
"inspect",
"feedback",
"sse",
"registry",
"users",
"invite",
"casebook",
"vault/config/metadata:read",
"orbital",
"enrich",
"oauth",
"collect",
"response",
"ui-settings",
"telemetry:write",
"openid",
"notification",
"global-intel:read",
"webhook",
"vault/config/posture:read",
"ao"
],
"updated-at": "2021-04-30T14:46:57.763Z",
"idp-mappings": [
{
"idp": "sxso",
"enabled?": true,
"user-identity-id": "00u4ti78a4BXlZSFQ357"
}
],
"user-email": "mafanta@cisco.com",
"user-name": "Martin Fanta",
"org-id": "827f573c-1c08-44a6-9d08-4b8ae03a50a0",
"user-id": "25de35b8-3069-4e5c-a1b4-506cfb82b6d5",
"enabled?": true,
"last-logged-at": [
"2021-04-30T14:47:33.023Z",
"2021-04-30T14:47:14.157Z",
"2021-04-30T14:47:00.478Z",
"2021-04-13T13:48:03.320Z",
"2021-03-18T13:14:51.114Z"
],
"created-at": "2021-03-18T13:14:24.604Z",
"user-nick": "Martin Fanta"
}
#+end_src
2021-04-30 17:10:36 +00:00
Org: =827f573c-1c08-44a6-9d08-4b8ae03a50a0=
#+begin_src js
{
"id": "827f573c-1c08-44a6-9d08-4b8ae03a50a0",
"name": "Global Threat Alerts Integrations - NAM",
"address": {
"city": "",
"street1": "",
"street2": "",
"department": "",
"postal-code": "",
"country-iso-code": "CZ"
},
"enabled?": true,
"created-at": "2021-03-18T13:14:24.597Z",
"scim-status": "activated"
}
#+end_src
2021-04-30 17:20:13 +00:00
***** APJC
User Martin Fanta
user-id: 25de35b8-3069-4e5c-a1b4-506cfb82b6d5
#+begin_src js
{
"role": "admin",
"scopes": [
"vault/configs:read",
"integration",
"private-intel",
"admin",
"profile",
"inspect",
"feedback",
"sse",
"registry",
"users",
"invite",
"casebook",
"vault/config/metadata:read",
"orbital",
"enrich",
"oauth",
"collect",
"response",
"ui-settings",
"telemetry:write",
"openid",
"notification",
"global-intel:read",
"webhook",
"vault/config/posture:read",
"ao"
],
"updated-at": "2021-04-30T14:46:57.763Z",
"idp-mappings": [
{
"idp": "sxso",
"enabled?": true,
"user-identity-id": "00u4ti78a4BXlZSFQ357"
}
],
"user-email": "mafanta@cisco.com",
"user-name": "Martin Fanta",
"org-id": "827f573c-1c08-44a6-9d08-4b8ae03a50a0",
"user-id": "25de35b8-3069-4e5c-a1b4-506cfb82b6d5",
"enabled?": true,
"last-logged-at": [
"2021-04-30T14:47:33.023Z",
"2021-04-30T14:47:14.157Z",
"2021-04-30T14:47:00.478Z",
"2021-04-13T13:48:03.320Z",
"2021-03-18T13:14:51.114Z"
],
"created-at": "2021-03-18T13:14:24.604Z",
"user-nick": "Martin Fanta"
}
#+end_src
2021-05-03 06:20:18 +00:00
** 2021-W18
*** 2021-05-03 Monday
2021-05-03 13:36:37 +00:00
**** CHAT Neel chat :work:chat:
:LOGBOOK:
2021-05-04 11:03:13 +00:00
CLOCK: [2021-05-03 Mon 15:35]--[2021-05-03 Mon 22:14] => 6:39
2021-05-03 13:36:37 +00:00
:END:
[2021-05-03 Mon 15:35]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-05-03 Monday][2021-05-03 Monday]]
2021-05-03 06:20:18 +00:00
**** IN-PROGRESS Check Provisioning API issue :work:
:LOGBOOK:
2021-05-03 13:36:37 +00:00
CLOCK: [2021-05-03 Mon 08:19]--[2021-05-03 Mon 11:43] => 3:24
2021-05-03 06:20:18 +00:00
:END:
[2021-05-03 Mon 08:19]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/inbox.org::*commander les légumes et les fruits][commander les légumes et les fruits]]
2021-05-04 11:03:13 +00:00
*** 2021-05-04 Tuesday
**** MEETING Town Hall :work:meeting:
:LOGBOOK:
2021-05-05 08:02:10 +00:00
CLOCK: [2021-05-04 Tue 13:02]--[2021-05-04 Tue 22:53] => 9:51
2021-05-04 11:03:13 +00:00
:END:
[2021-05-04 Tue 13:01]
- ref ::
Mougin Office
2021-05-04 11:06:07 +00:00
2021-05-04 11:07:23 +00:00
Decision par: Business Unit Engineering (Securite) et Sales supportent
aussi.
2021-05-04 11:11:00 +00:00
Râlage, ...
2021-05-04 11:17:02 +00:00
Remise en cause des chiffres WPR par Luc.
Explication:
5 sites Regus au lieu d'un seul.
2021-05-04 11:18:34 +00:00
Alexandra Viennot; HR Country Manager.
2021-05-05 08:02:10 +00:00
*** 2021-05-05 Wednesday
2021-05-05 15:33:23 +00:00
**** CHAT Fix client in APJC :work:chat:
:LOGBOOK:
2021-05-06 15:04:46 +00:00
CLOCK: [2021-05-05 Wed 17:32]--[2021-05-05 Wed 18:49] => 1:17
2021-05-05 15:33:23 +00:00
:END:
[2021-05-05 Wed 17:32]
client-94325fbf-986f-4f0d-ae1d-c1696d1825f0
2021-05-05 12:51:52 +00:00
**** CHAT Tritan York question :work:chat:
:LOGBOOK:
2021-05-05 15:33:23 +00:00
CLOCK: [2021-05-05 Wed 14:50]--[2021-05-05 Wed 17:32] => 2:42
2021-05-05 12:51:52 +00:00
:END:
[2021-05-05 Wed 14:50]
2021-05-05 12:41:26 +00:00
**** IN-PROGRESS Admin UI :work:
:LOGBOOK:
2021-05-05 12:51:52 +00:00
CLOCK: [2021-05-05 Wed 14:40]--[2021-05-05 Wed 14:50] => 0:10
2021-05-05 12:41:26 +00:00
:END:
[2021-05-05 Wed 14:40]
2021-05-05 12:31:41 +00:00
**** CHAT April Luk testing :work:chat:interruption:
:LOGBOOK:
2021-05-05 12:41:26 +00:00
CLOCK: [2021-05-05 Wed 14:30]--[2021-05-05 Wed 14:40] => 0:10
2021-05-05 12:31:41 +00:00
:END:
[2021-05-05 Wed 14:30]
- ref ::
2021-05-05 08:02:10 +00:00
**** REVIEW PR reviewing :work:review:
:LOGBOOK:
2021-05-05 08:19:28 +00:00
CLOCK: [2021-05-05 Wed 09:01]--[2021-05-05 Wed 10:18] => 1:17
2021-05-05 08:02:10 +00:00
:END:
[2021-05-05 Wed 10:01]
- ref ::
2021-05-06 15:04:46 +00:00
*** 2021-05-06 Thursday
**** MEETING Weekly :work:meeting:
:LOGBOOK:
2021-05-10 06:59:58 +00:00
CLOCK: [2021-05-06 Thu 17:03]--[2021-05-07 Fri 00:22] => 7:19
2021-05-06 15:04:46 +00:00
:END:
[2021-05-06 Thu 17:03]
2021-05-06 15:10:56 +00:00
***** Standup
****** Yann
- Fixed a bug related to CSA Migration and follow up
- Device Code Flow
2021-05-06 15:14:48 +00:00
.
****** Ereteo
****** Matt
Module types
2021-05-06 15:17:28 +00:00
Question for Jyoti.
2021-05-06 15:19:45 +00:00
- n AMP -> 1 secure X
.
2021-05-06 15:22:44 +00:00
****** Ambrose
2021-05-06 15:24:10 +00:00
2021-05-06 15:22:44 +00:00
- merged the 2nd/3 of Status API yesterday
- fixed 1.72 deploy due to rate-limiting
2021-05-06 15:24:10 +00:00
=> moving to actions
2021-05-06 15:26:39 +00:00
****** Rob
Trent suggested a solution
New UI idea underway.
Change the data on the ESA module side.
2021-05-06 15:27:52 +00:00
Horizontal segment, total of the segment and part of the total.
2021-05-06 15:28:58 +00:00
Jyoti: we want the product involved (ESA team) Paul Infantino.
Tangling SMA. Confusing myself.
2021-05-06 15:31:58 +00:00
Jyoti to Guillaume: On the UI side applinks.
Dar implementing it.
And he fetches it, and uses the bookmark Okta.
2021-05-06 15:33:20 +00:00
Guillaume: we gave you.
2021-05-06 15:35:09 +00:00
****** Victor
Module Type Patch API.
2021-05-06 15:36:25 +00:00
****** Mark
2021-05-06 15:37:35 +00:00
Delete AO Setup workflow.
Really good test on that.
2021-05-06 15:39:12 +00:00
****** Ag
This one pretty close to be done.
I used generative test.
Generate
2021-05-06 15:49:40 +00:00
****** Jyoti
Meeting CSA Migration.
2021-05-10 06:59:58 +00:00
** 2021-W19
*** 2021-05-10 Monday
2021-05-10 07:04:09 +00:00
**** EMAIL Answer to Jyoti email :work:email:
:LOGBOOK:
CLOCK: [2021-05-10 Mon 09:03]
CLOCK: [2021-05-10 Mon 09:00]--[2021-05-10 Mon 09:00] => 0:00
:END:
[2021-05-10 Mon 09:00]
- ref :: [[file:~/Library/Mobile Documents/iCloud~com~appsonthemove~beorg/Documents/org/tracker.org::*2021-05-10 Monday][2021-05-10 Monday]]