Project

General

Profile

Activity

From 07/04/2023 to 08/02/2023

08/02/2023

01:48 PM Feature #3931: single sign-on for virtual desktop mode
> > > RPC WebClientLauncher.spawn with SSO
> >
> > This still needs to be discussed. We have a customer that orig...
Greg Shah
01:41 PM Feature #3931: single sign-on for virtual desktop mode
> The @BrokerServerServices@ acl/net config described [[p2j:Remote_Launchers|here]] seems outdated. Does it need to b... Greg Shah
09:55 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> > RPC WebClientLauncher.spawn with SSO
>
> This still needs to be discussed. We have a custom...
Galya B
09:31 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Do we feed the default user explicitly?
Actually my bad, it's already done in the latest revision ...
Galya B
09:23 AM Feature #3931: single sign-on for virtual desktop mode
And here is my conclusion on the other topic:
* @remotelaunchoption@ checks to be executed only for remote spawns (u...
Galya B
09:01 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> I don't think we should allow FWD to determine a default is required - the SSO authentic...
Galya B
08:57 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Greg Shah wrote:
> > I think the answer here is to provide a facility for the authenticator to get...
Constantin Asofiei
08:55 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> I think the answer here is to provide a facility for the authenticator to get some configuration ...
Galya B
08:47 AM Feature #3931: single sign-on for virtual desktop mode
> 1. Do you want a configurable FWD user for when SSO Authenticator (customer) doesn't know what it wants for securit... Greg Shah
08:39 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> I would not expect there to be a default os user that is not specified in the directory, but I do...
Galya B
08:38 AM Feature #3931: single sign-on for virtual desktop mode
> @GuestAccess@ has nothing to do with SSO, not a single bit, so let's not get it involved in the discussion. Both au... Greg Shah
08:35 AM Feature #3931: single sign-on for virtual desktop mode
> Do you want a default os user if none is specified in directory?
I would not expect there to be a default os use...
Greg Shah
08:31 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> Galya B wrote:
> > Let me just explain it that way: SSO with a default FWD user and a d...
Galya B
08:31 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Let me just explain it that way: SSO with a default FWD user and a default OS user is called @Guest...
Constantin Asofiei
08:30 AM Feature #3931: single sign-on for virtual desktop mode
Let me just explain it that way: SSO with a default FWD user and a default OS user is called @GuestAccess@. Galya B
08:24 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> > Default FWD user for SSO
>
> Are you asking if we still need to support @GuestAccess@ or som...
Galya B
08:19 AM Feature #3931: single sign-on for virtual desktop mode
> RPC WebClientLauncher.spawn with SSO
This still needs to be discussed. We have a customer that originally plann...
Greg Shah
08:15 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> I think this was about securing the entry points (e.g. @client:cmd-line-option:startup-procedure@...
Constantin Asofiei
08:12 AM Feature #3931: single sign-on for virtual desktop mode
> Since both checks were omitted with VD before, I want to know if it makes sense to enable them for regular VD spawn... Greg Shah
08:08 AM Feature #3931: single sign-on for virtual desktop mode
> > @remotelaunchoption@ I guess is allowing the fwd user to send certain options to the client. Why is it called rem... Greg Shah
08:05 AM Feature #3931: single sign-on for virtual desktop mode
> @trustedspawner@ I guess is allowing the fwd user to spawn a new process without os password.
Correct
> @remo...
Greg Shah
06:06 AM Feature #3931: single sign-on for virtual desktop mode
Configs for testing:... Galya B
06:03 AM Feature #3931: single sign-on for virtual desktop mode
r14659 up, all code review requests addressed.
I'll be waiting for *answers* to my questions and further *code re...
Galya B
05:27 AM Feature #3931: single sign-on for virtual desktop mode
Actually is it possible to determine the fwd user for Virtual Desktop running without SSO? For the connection auth wi... Galya B
04:55 AM Feature #3931: single sign-on for virtual desktop mode
SSO Features Support:
|Feature|Planned|
|SSL connection authentication + SSO|❌|
|OS account pools|❌|
|RPC WebCl...
Galya B
04:37 AM Feature #3931: single sign-on for virtual desktop mode
Since both checks were omitted with VD before, I want to know if it makes sense to enable them for regular VD spawn r... Galya B
04:35 AM Feature #3931: single sign-on for virtual desktop mode
I have a question about the security checks, that are for the plugins @trustedspawner@ and @remotelaunchoption@: what... Galya B

08/01/2023

03:28 AM Feature #3931: single sign-on for virtual desktop mode
I'll soon apply the changes with the latest revision, so when you have time, you can also check the initial refactori... Galya B
02:28 AM Feature #3931: single sign-on for virtual desktop mode
Check how @auth-plugins@ works with @GuestAccess@ - something similar can be done for the guest SSO plugin (we should... Constantin Asofiei
02:21 AM Feature #3931: single sign-on for virtual desktop mode
The fwd user attr @<node-attribute name="osuser" value="[os-user]"/>@ can't be replaced by a default. That's how the ... Galya B

07/31/2023

12:59 PM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> I mean we can still use @bogus@. When I'm done with the work, I'll change it to @bogus@ and will ad...
Constantin Asofiei
12:10 PM Feature #3931: single sign-on for virtual desktop mode
I mean we can still use @bogus@. When I'm done with the work, I'll change it to @bogus@ and will add @<node-attribute... Galya B
12:06 PM Feature #3931: single sign-on for virtual desktop mode
I created the @SsoAuthenticatorSample@ and hardcoded fwd user @newuser@ that can use any os user configured for it.
...
Galya B
12:02 PM Feature #3931: single sign-on for virtual desktop mode
Thanks for the explanation.
Greg, just an idea: it would be helpful for i.e. development mode to have a 'GuestSSOP...
Constantin Asofiei
11:55 AM Feature #3931: single sign-on for virtual desktop mode
Correct. This will be pure Java and will not have a context. Greg Shah
11:52 AM Feature #3931: single sign-on for virtual desktop mode
Basically we can't have a context before determining the fwd user that is returned by the SSO auth, so it should run ... Galya B
11:49 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> I don't understand; from looking at the code, the default value for @Thread.defaultUncau...
Galya B
11:15 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Constantin Asofiei wrote:
> > Review for 3931a rev 14653:
> > * @ClientDriver.main@ - @defaultUnc...
Constantin Asofiei
09:10 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> Review for 3931a rev 14653:
> * @ClientDriver.main@ - @defaultUncaughtExceptionHandler@...
Galya B
07:13 AM Feature #3931: single sign-on for virtual desktop mode
Review for 3931a rev 14653:
* @ClientDriver.main@ - @defaultUncaughtExceptionHandler@ can be null
* @SchemaComparat...
Constantin Asofiei
07:20 AM Bug #7646: FILL-IN: NPE during the PASTE of non-text clipboard contents
Greg Shah wrote:
> Instead of applying the fix to trunk directly, I prefer to just include the fix in another branch...
Vladimir Tsichevski
07:10 AM Bug #7646: FILL-IN: NPE during the PASTE of non-text clipboard contents
Greg Shah wrote:
> Instead of applying the fix to trunk directly, I prefer to just include the fix in another branch...
Vladimir Tsichevski
07:09 AM Bug #7646: FILL-IN: NPE during the PASTE of non-text clipboard contents
Instead of applying the fix to trunk directly, I prefer to just include the fix in another branch where you are alrea... Greg Shah
06:46 AM Bug #7646: FILL-IN: NPE during the PASTE of non-text clipboard contents
Greg Shah wrote:
> Do we need a task for this? The fix seems trivial.
I think we don't. I can fix this in the tr...
Vladimir Tsichevski
06:44 AM Bug #7646: FILL-IN: NPE during the PASTE of non-text clipboard contents
Do we need a task for this? The fix seems trivial. Greg Shah
06:28 AM Bug #7646 (WIP): FILL-IN: NPE during the PASTE of non-text clipboard contents
Scenario:
# there is no *text* contents in system-wide clipboard (for example, the user copied an image to clipboa...
Vladimir Tsichevski
06:05 AM Bug #7646 (Merge Pending): FILL-IN: NPE during the PASTE of non-text clipboard contents
Vladimir Tsichevski

07/28/2023

03:59 PM Bug #7515: FILL-IN: editing dates issues
Vladimir Tsichevski wrote:
> Yet another issue: normally pressing @?@ (question) should always reset screen value to...
Vladimir Tsichevski
11:41 AM Bug #7515: FILL-IN: editing dates issues
**#9855 (FIXED)** Yet another issue:
Test program:...
Vladimir Tsichevski
02:53 PM Bug #7642: Assigning SESSION:DATE-FORMAT has no effect on existing date instances
Run this program. Assume the default date format is @mdy@ (as set in @directory.xml@).... Vladimir Tsichevski
02:39 PM Bug #7642 (WIP): Assigning SESSION:DATE-FORMAT has no effect on existing date instances
Vladimir Tsichevski

07/27/2023

08:59 AM Bug #7515: FILL-IN: editing dates issues
**(FIXED)** Yet another issue: normally pressing @?@ (question) should always reset screen value to an empty string.
...
Vladimir Tsichevski

07/25/2023

11:21 AM Feature #3931: single sign-on for virtual desktop mode
Now a question about
> allowed to spawn a new session
The @BrokerServerServices@ acl/net config described [[p2j:R...
Galya B
11:11 AM Feature #3931: single sign-on for virtual desktop mode
The current web flow is:
@WebHandler.spawnWorker@ -> @(Web)ClientSpawner.spawn@ -> [broker for the os user is found]...
Galya B
09:45 AM Feature #3931: single sign-on for virtual desktop mode
By "any authorized context", I mean a context and caller that is allowed to spawn a new session. Greg Shah
09:42 AM Feature #3931: single sign-on for virtual desktop mode
Yes, brokers need to be supported. This is just a spawning mechanism it should not really be core to the concept of ... Greg Shah
09:27 AM Feature #3931: single sign-on for virtual desktop mode
Actually that is not correct. The broker is used just for spawning a separate process, so the connection to the serve... Galya B
09:12 AM Feature #3931: single sign-on for virtual desktop mode
Brokers are currently using only certificate authentication before the server and the session is running for the whol... Galya B
11:13 AM Bug #7515: FILL-IN: editing dates issues
**ISSUE** Yet another issue: if a just open a date @FILL-IN@, place the cursor at any of the two delimiters and press... Vladimir Tsichevski

07/24/2023

03:31 PM Bug #7515: FILL-IN: editing dates issues
**ISSUE** Yet another issue:
In OE the @SCREEN-VALUE@ called for an unedited date @FILL-IN@ with unknown variable,...
Vladimir Tsichevski
09:39 AM Feature #3931: single sign-on for virtual desktop mode
Just to mention, so that no unexpected surprises are found down the road: "sso hook" is a bit exaggerated for what I'... Galya B
09:35 AM Feature #3931: single sign-on for virtual desktop mode
It would be feasible to implement certificate validation + SSO with the customer hook returning the certificate to us... Greg Shah
09:22 AM Feature #3931: single sign-on for virtual desktop mode
With SSO it can't be of type @AUTH_MODE_X509_IDPW@ (except if we don't modify it), because the fwd user is dynamic (c... Galya B
09:20 AM Feature #3931: single sign-on for virtual desktop mode
I mean the connection between the FWD client process (with embedded web server) and the FWD server. Galya B
09:18 AM Feature #3931: single sign-on for virtual desktop mode
> My question is if it should be an option to enable certificate validation + SSO?
Help me understand how would it...
Greg Shah
02:00 AM Feature #3931: single sign-on for virtual desktop mode
I didn't notice @AUTH_MODE_X509_IDPW@, @AUTH_MODE_X509_IDPW@ does indeed both validations, but the FWD user is either... Galya B

07/21/2023

03:07 PM Bug #7633: some trigger issues: PAUSE must not raise a trigger and no PAUSE exists when UPDATE is...
There is this test:... Constantin Asofiei
03:07 PM Bug #7633 (New): some trigger issues: PAUSE must not raise a trigger and no PAUSE exists when UPD...
Constantin Asofiei
01:00 PM Feature #3931: single sign-on for virtual desktop mode
> At the moment, as far as I understand the logic, authentication is either certificate check, or fwd users check.
...
Greg Shah
11:06 AM Feature #3931: single sign-on for virtual desktop mode
What I mean is having certificate should not limit the number of associated fwd users. Isn't it good to have clients ... Galya B
11:03 AM Feature #3931: single sign-on for virtual desktop mode
At the moment, as far as I understand the logic, authentication is either certificate check, or fwd users check. If @... Galya B
10:51 AM Feature #3931: single sign-on for virtual desktop mode
r14653: @GuestAccess@ reverted. Sso connection authentication is @SecurityManager.authenticateClientWorkerSso@ client... Galya B
08:55 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> My references above are only discussing web clients. Of course, batch and non-web clients should...
Galya B
08:49 AM Feature #3931: single sign-on for virtual desktop mode
> > > Are we moving all customers using embedded to SSO?
> >
> > Yes.
> Let me verify I understand correctly. C...
Greg Shah
08:46 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> > Are we moving all customers using embedded to SSO?
>
> Yes.
Let me verify I understand co...
Galya B
08:46 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> So batch processes will run on that server with SSO? @auth-config/plugin@ defines @GuestAccess@ use...
Greg Shah
08:42 AM Feature #3931: single sign-on for virtual desktop mode
> Are we moving all customers using embedded to SSO?
Yes. We already have a hacked-up way to do this. With #3770...
Greg Shah
08:40 AM Feature #3931: single sign-on for virtual desktop mode
So batch processes will run on that server with SSO? @auth-config/plugin@ defines @GuestAccess@ used by batch. Do I r... Galya B
08:39 AM Feature #3931: single sign-on for virtual desktop mode
> > * I would expect us to drop usage of @GuestAccess@ in the solution. It is a hack that is not important/is unwant... Greg Shah
08:37 AM Feature #3931: single sign-on for virtual desktop mode
To summarize embedded spawning / launching options:
1. [Old] web request to @/embedded/launch@ runs without knowing ...
Galya B
08:30 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> So it is cleaner if we don't have an existing context and instead we should take the passed in ap...
Galya B
08:28 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Actually for rpc calls to @spawn@ thread pool is not used, because security context should be avail...
Greg Shah
08:27 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> It sounds like you are mixing two different authenticator implementations together which may caus...
Galya B
08:24 AM Feature #3931: single sign-on for virtual desktop mode
> Is there any reason why this is not a good solution?
We'll see. I will have to look at the code. It sounds lik...
Greg Shah
08:23 AM Feature #3931: single sign-on for virtual desktop mode
Actually for rpc calls to @spawn@ thread pool is not used, because security context should be available. The Thread p... Galya B
08:17 AM Feature #3931: single sign-on for virtual desktop mode
> That being said, I'm still not sure what security context spawning should be executed under to be able to authenti... Greg Shah
08:10 AM Feature #3931: single sign-on for virtual desktop mode
> > * As noted in #4129, the pooling side of things is not critical right now. [...] For that reason, I'd prefer to k... Greg Shah
03:52 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> In regard to unifying the spawning logic and the authentication changes, I'll have to just look a...
Galya B
03:50 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> * I would expect us to drop usage of @GuestAccess@ in the solution. It is a hack that is not imp...
Galya B
03:45 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> * I would expect us to drop usage of @GuestAccess@ in the solution. It is a hack that is not imp...
Galya B
03:31 AM Feature #3931: single sign-on for virtual desktop mode
That being said, I'm still not sure what security context spawning should be executed under to be able to authentica... Galya B
03:25 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> * We have one customer that plans a separate web server for their embedded environment and all th...
Galya B
03:16 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> * As noted in #4129, the pooling side of things is not critical right now. [...] For that reason,...
Galya B

07/20/2023

12:37 PM Bug #7515: FILL-IN: editing dates issues
*(FIXED)* Another issue found:
In a @character@ or @date@ @FILL-IN@:
# the cursor is in the leftmost position
...
Vladimir Tsichevski
11:29 AM Feature #3931: single sign-on for virtual desktop mode
I don't have time to do a full code review.
Some quick feedback:
* As noted in #4129, the pooling side of thing...
Greg Shah
11:14 AM Feature #3931: single sign-on for virtual desktop mode
> Do we have customers using brokers with web (VD / embedded)?
Not in production today but it should be supported.
Greg Shah
10:38 AM Feature #3931: single sign-on for virtual desktop mode
Do we have customers using brokers with web (VD / embedded)? Galya B
10:29 AM Feature #3931: single sign-on for virtual desktop mode
Early review required on 3931a r14652 based on trunk r14637.
What was done:
* adding @/sso/gui@, @/sso/chui@ and ...
Galya B

07/13/2023

10:27 AM Feature #3931: single sign-on for virtual desktop mode
Also another question: the spawn calls to the brokers run at the moment in different contexts. Embedded has this cert... Galya B
10:11 AM Feature #3931: single sign-on for virtual desktop mode
@certificates/peers@ and @private-keys@ are probably needed for the server <-> server connection auth for rpc calls, ... Galya B
10:02 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> * connect to the FWD server and authenticate via a certificate for a FWD process account...
Galya B
09:50 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> * call into the FWD server via @WebClientLauncher.launch@, where it can specify *any OS ...
Galya B
09:37 AM Feature #3931: single sign-on for virtual desktop mode
No, this is not the single reason. I forgot to mention that the embedded app (for i.e. Hotel GUI) can be ran in stan... Constantin Asofiei
09:36 AM Feature #3931: single sign-on for virtual desktop mode
Ok, here goes my proposal for lean code:
1. Expose a method from @SecurityManager@ that checks @trustedspawner/resou...
Galya B
09:26 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> > 1. Why is there a certificate specified for embedded? I still don't get that as well. ...
Galya B
09:13 AM Feature #3931: single sign-on for virtual desktop mode
Galya, the point of:... Constantin Asofiei
09:07 AM Feature #3931: single sign-on for virtual desktop mode
Also:
1. Why is there a certificate specified for embedded? I still don't get that as well. Is it for the same check...
Galya B
08:58 AM Feature #3931: single sign-on for virtual desktop mode
That was pseudo-code of course, but my point is that I still don't see a good reason to keep the context. Galya B
08:56 AM Feature #3931: single sign-on for virtual desktop mode
Ok, let's get it straight: @EmbeddedWebHandler@ checks if @webClient/defaultAccount@ is the same as @trustedspawner/r... Galya B
08:44 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Constantin Asofiei wrote:
> > Galya B wrote:
> > > Directory configs under @server/default/embedd...
Constantin Asofiei
08:34 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> Galya B wrote:
> > Directory configs under @server/default/embeddedWebApp@ are all used...
Galya B
08:03 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Directory configs under @server/default/embeddedWebApp@ are all used only in @EmbeddedWebAppHandler...
Constantin Asofiei
08:00 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> > I don't know how to feed the fwd user from @WebHandler@ @spawnWorker@ (contained in @SsoAuthent...
Galya B
07:46 AM Feature #3931: single sign-on for virtual desktop mode
Directory configs under @server/default/embeddedWebApp@ are all used only in @EmbeddedWebAppHandler.AuthWorker@. That... Galya B
07:34 AM Feature #3931: single sign-on for virtual desktop mode
Enabling trusted for VD (which is currently not possible) should probably be done the same way as embedded. But the c... Galya B
07:27 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> I suspect we need to add another @AUTH_MODE_*@ and associated logic to bypass our own authenticat...
Galya B
07:21 AM Feature #3931: single sign-on for virtual desktop mode
Very good explanation, will be helpful for everyone jumping in later on. Unfortunately I already got it figured out b... Galya B
07:03 AM Feature #3931: single sign-on for virtual desktop mode
> The auth code in @SecurityManager@ (@authenticateClientWorker@ / @authenticateLocal@) is very special and I don't f... Greg Shah
06:50 AM Feature #3931: single sign-on for virtual desktop mode
@TrustedSpawnerResource@ is not specific to embedded mode. It could be used in virtual desktop mode to avoid the PAM... Greg Shah
06:45 AM Feature #3931: single sign-on for virtual desktop mode
Some context and decision criteria:
* The reason this task is entitled "single sign-on for virtual desktop mode" i...
Greg Shah
06:23 AM Feature #3931: single sign-on for virtual desktop mode
It's not nit picking, I really need to get to the bottom of it to be able to rework those to accommodate for SSO and ... Galya B
06:14 AM Feature #3931: single sign-on for virtual desktop mode
VD works with OS user / pass, they auth in PAM -> pass.
Embedded works with certificates associated with alias assoc...
Galya B
06:09 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> Why do we need checks for @TrustedSpawnerResource@ ? It's very imaginary to me, we create an imagin...
Constantin Asofiei
06:06 AM Feature #3931: single sign-on for virtual desktop mode
I mean obviously spawner doesn't require specific auth to call the process and it works with passwordless. If the ser... Galya B
06:04 AM Feature #3931: single sign-on for virtual desktop mode
Constantin Asofiei wrote:
> Galya B wrote:
> > I see @EmbeddedWebAppHandler@ is created by Constantin and he can ex...
Galya B
06:00 AM Feature #3931: single sign-on for virtual desktop mode
Galya B wrote:
> I see @EmbeddedWebAppHandler@ is created by Constantin and he can explain us better why @AuthWorker...
Constantin Asofiei
05:48 AM Feature #3931: single sign-on for virtual desktop mode
> Embedded doesn't have a default landing page, while VD has. For embedded @index.html@ where @<iframe id="embeddedP2... Greg Shah
05:47 AM Feature #3931: single sign-on for virtual desktop mode
I see @EmbeddedWebAppHandler@ is created by Constantin and he can explain us better why @AuthWorker@ exists. Galya B
05:45 AM Feature #3931: single sign-on for virtual desktop mode
Greg Shah wrote:
> > I'm trying to understand why virtual desktop runs without security context and bypasses securit...
Galya B
05:42 AM Feature #3931: single sign-on for virtual desktop mode
I'm speaking only about the spawning process and the Thread with the security context doesn't do anything to my knowl... Galya B
05:42 AM Feature #3931: single sign-on for virtual desktop mode
> I'm trying to understand why virtual desktop runs without security context and bypasses security checks, while embe... Greg Shah
05:40 AM Feature #3931: single sign-on for virtual desktop mode
> I'm not sure if I've messed up something or this is how embedded is supposed to work, but when I define a startup p... Greg Shah
05:33 AM Feature #3931: single sign-on for virtual desktop mode
VD has this line @sp.bypass = !SecurityManager.getInstance().hasContext();@. Galya B
05:31 AM Feature #3931: single sign-on for virtual desktop mode
It is like the server says: Let me check my configs. ... a lot going on ... I'm all good. Now do the same as VD that ... Galya B
05:29 AM Feature #3931: single sign-on for virtual desktop mode
According to the comments in the code it seems related to @trusted@ mode, but it still doesn't make sense. Galya B
05:27 AM Feature #3931: single sign-on for virtual desktop mode
I'm trying to understand why virtual desktop runs without security context and bypasses security checks, while embedd... Galya B
05:25 AM Feature #3931: single sign-on for virtual desktop mode
> Is it... is it... the remote spawn that needs proper security context?
I don't understand the question. Securit...
Greg Shah
04:37 AM Feature #3931: single sign-on for virtual desktop mode
Is it... is it... the remote spawn that needs proper security context? Galya B

07/12/2023

02:37 PM Bug #7515 (WIP): FILL-IN: editing dates issues
Vladimir Tsichevski
12:20 PM Bug #7515: FILL-IN: editing dates issues
Vladimir Tsichevski wrote:
> # Also, if the cursor was located in the rightmost position before the operation, the...
Vladimir Tsichevski
07:34 AM Bug #7515: FILL-IN: editing dates issues
Please do check ChUI for each case because the ChUI rules may have differences. Also note that ChUI has a very speci... Greg Shah
07:19 AM Bug #7515: FILL-IN: editing dates issues
Vladimir Tsichevski wrote:
> In FWD selection is *not* erased.
According to the comments in the Java code, this...
Vladimir Tsichevski
11:37 AM Feature #3931: single sign-on for virtual desktop mode
I'm not sure if I've messed up something or this is how embedded is supposed to work, but when I define a startup pro... Galya B
08:05 AM Feature #3931: single sign-on for virtual desktop mode
H * E * L * P
I don't understand something basic. Why does it matter what security context spawns the web client? ...
Galya B
06:58 AM Feature #3931: single sign-on for virtual desktop mode
Embedded doesn't have a default landing page, while VD has. For embedded @index.html@ where @<iframe id="embeddedP2J"... Galya B

07/11/2023

05:01 PM Bug #7515: FILL-IN: editing dates issues
*(FIXED)* At least two issues when editing date with @FILL-IN@.
# When the user presses @Ctrl-A@ to select all, th...
Vladimir Tsichevski
04:49 PM Bug #7515 (WIP): FILL-IN: editing dates issues
Vladimir Tsichevski
09:20 AM Feature #3931: single sign-on for virtual desktop mode
The auth code in @SecurityManager@ (@authenticateClientWorker@ / @authenticateLocal@) is very special and I don't fee... Galya B
09:05 AM Feature #4129: map web client users to OS accounts
Greg Shah wrote:
> That seems in conflict with your comment "All OS users will have to have password defined for web...
Galya B
08:49 AM Feature #4129: map web client users to OS accounts
> As discussed earlier with SSO enabled both modes will have to be available for both drivers.
This is my expectio...
Greg Shah
04:14 AM Feature #4129: map web client users to OS accounts
Greg Shah wrote:
> > If a new Authenticator for Virtual Desktop is introduced does it have to be integrated with all...
Galya B

07/10/2023

04:33 PM Feature #4129: map web client users to OS accounts
> My question is if there can be different auth modes for different processes or it is only one for all?
Yes, it s...
Greg Shah

07/07/2023

11:07 AM Feature #3931: single sign-on for virtual desktop mode
Also it's so convenient, I can already imagine the constant lack of ports if no restrictions are imposed. Galya B
09:55 AM Feature #3931: single sign-on for virtual desktop mode
If auto-login is supported and the cookie is not deleted on session completion, the redirect back to the login page w... Galya B
03:11 AM Feature #4854: origin affinity
OK, it can be made simpler. I've just tested it. A httpOnly cookie can be sent and received from @doPost@ and @doGet@... Galya B
02:47 AM Feature #4854: origin affinity
A subdomain is a more pretty solution, if the admin is in the mood to configure DNS. Galya B
02:46 AM Feature #4854: origin affinity
Hynek Cihlar wrote:
> A typical scenario is that the main site and the embedded FWD legacy app are coming from diffe...
Galya B
02:34 AM Feature #4854: origin affinity
Galya B wrote:
> Hynek Cihlar wrote:
> > For plain virtual desktop this is true. However for embedded mode you can'...
Hynek Cihlar
02:18 AM Feature #4854: origin affinity
Hynek Cihlar wrote:
> For plain virtual desktop this is true. However for embedded mode you can't assume anything ab...
Galya B
02:17 AM Feature #4854: origin affinity
Galya B wrote:
> On the other hand browser extensions seem to be able to access @httpOnly@ cookies as well as @local...
Hynek Cihlar
02:15 AM Feature #4854: origin affinity
Galya B wrote:
> Hynek Cihlar wrote:
> > It looks good. The only downside I see are the security implications stori...
Hynek Cihlar
02:00 AM Feature #4854: origin affinity
On the other hand browser extensions seem to be able to access @httpOnly@ cookies as well as @localStorage@. Galya B
01:57 AM Feature #4854: origin affinity
Hynek Cihlar wrote:
> It looks good. The only downside I see are the security implications storing sensitive data in...
Galya B
01:49 AM Feature #4854: origin affinity
Galya B wrote:
> Hynek Cihlar wrote:
> > For the auto login you want to store any secure access token as session co...
Hynek Cihlar
01:14 AM Feature #4854: origin affinity
Constantin Asofiei wrote:
> Galya, you mean that Virtual Desktop will be run in an iframe? If so, we need to be pret...
Galya B
01:12 AM Feature #4854: origin affinity
Hynek Cihlar wrote:
> For the auto login you want to store any secure access token as session cookie. But this can't...
Galya B

07/06/2023

02:12 PM Feature #4854: origin affinity
Greg Shah wrote:
> > But I'm not sure how would this help with the auto login feature.
>
> I think the idea was t...
Hynek Cihlar
01:26 PM Feature #4854: origin affinity
> But I'm not sure how would this help with the auto login feature.
I think the idea was that the main/parent page...
Greg Shah
12:44 PM Feature #4854: origin affinity
Galya, you mean that Virtual Desktop will be run in an iframe? If so, we need to be pretty sure that the 'virtual des... Constantin Asofiei
12:31 PM Feature #4854: origin affinity
Greg Shah wrote:
> Hynek/Sergey: Do you have any thoughts?
Interesting idea. This could lead to some issues with ...
Hynek Cihlar
11:24 AM Feature #4854: origin affinity
Greg Shah wrote:
> I do wonder if we have anything in the virtual desktop mode that will need to be changed to be OK...
Galya B
11:18 AM Feature #4854: origin affinity
Actually there is one more: server-side storage stores all client prefs in one place, so it needs to know how to diff... Galya B
11:16 AM Feature #4854: origin affinity
Greg Shah wrote:
> On the other hand, we were already going down the server-side storage.
The only concern I have ...
Galya B
11:13 AM Feature #4854: origin affinity
I have no strong objection. We use this approach already in Embedded Mode. I do wonder if we have anything in the v... Greg Shah
11:03 AM Feature #4854: origin affinity
I have one of those ideas I get smashed for having: Put login screen / web driver container in an iframe. Why?
1. Th...
Galya B

07/05/2023

12:53 PM Feature #3931: single sign-on for virtual desktop mode
I'm still not sure if we need to enable SSO server-wide or just for certain clients. When SSO will be server-wide alw... Galya B
12:45 PM Feature #3931: single sign-on for virtual desktop mode
Sandbox in 3931a based on trunk 14637, commits 14638 & 14639.
What I did:
* The same login page and POST request ...
Galya B
08:14 AM Feature #3931: single sign-on for virtual desktop mode
> I guess we want to make Virtual Desktop allow association of fwd users to os users without passwords with trusted s... Greg Shah
08:13 AM Feature #3931: single sign-on for virtual desktop mode
> But I'm not sure if changing the @auth-plugin@ to a new that serves the SSO flow will affect other clients that are... Greg Shah

07/04/2023

01:43 PM Feature #3931 (WIP): single sign-on for virtual desktop mode
Branch 3931a created. Galya B
 

Also available in: Atom