Details

    • AppSec Iteration 59, AppSec Iteration 60

    Description

      Confluence page

      https://liferay.atlassian.net/wiki/spaces/ENGAPPSECURITY/pages/1481736505/Doc+Documentation+of+the+Story+As+an+Instance+Administrator+I+want+to+see+if+registered+applications+for+OAuth2+is+a+trusted+application+or+the+Remember+My+Authorization+is+checked+for+them

      Background
      This feature is added to be able to quick review if an application has activated any of the extra properties associated with the Authorization Code or Authorization Code PKCE: Trusted Application or Remember Device.
      It will be useful for OAuth2 Administrators, they can check in the list of OAuth2 applications which have one of these two options activated.

      Features
      A new column is present on the OAuth 2 Administration menu, in this list a new column "Extra Properties" it's available and indicates whether the application has the Trusted Application or Remember Device option activated.
      It should be noted that when an application has the "trusted" option, it can never also be marked as a "Remember Device", so only one of this options will be available in this column (or no value will be displayed if not applicable).

      Steps
      Just go to Control Panel - Security - OAuth 2 Administration and that new column will be available (see attached screenshoot).

      Code

      Attachments

        Issue Links

          Activity

            People

              tibor.lipusz Tibor Lipusz
              nora.szel Nóra Szél
              Marta Elicegui Marta Elicegui
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:
                2 years, 9 weeks, 3 days ago

                Packages

                  Version Package