Skip to content

docs(jans-cedarling): documentation refactor for cedarling #11192

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 8 commits into from
May 16, 2025

Conversation

SafinWasi
Copy link
Contributor

Prepare


Description

Target issue

closes #11191

Implementation Details


Test and Document the changes

N/A

Please check the below before submitting your PR. The PR will not be merged if there are no commits that start with docs: to indicate documentation changes or if the below checklist is not selected.

  • I confirm that there is no impact on the docs due to the code changes in this PR.

Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>
Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>
@mo-auto mo-auto added area-documentation Documentation needs to change as part of issue or PR comp-docs Touching folder /docs comp-jans-cedarling Touching folder /jans-cedarling labels Apr 7, 2025
nynymike
nynymike previously approved these changes Apr 7, 2025
Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>
rmarinn
rmarinn previously approved these changes Apr 11, 2025
Signed-off-by: ossdhaval <343411+ossdhaval@users.noreply.github.com>
@@ -35,4 +35,34 @@ If the Cedarling property `CEDARLING_ID_TOKEN_TRUST_MODE` is `Strict`, the Cedar

### JWT Status Validation

The Cedarling can also check for JWT revocation if you have the `CEDARLING_JWT_STATUS_VALIDATION` property `Enabled`. The Cedarling checks the status bit of the Status Token JWT, as described in the [OAuth Status Lists](https://datatracker.ietf.org/doc/draft-ietf-oauth-status-list/) draft. Token status enforcement mitigates account takeover by enabling immediate revocation of all tokens issued to an attacker.
Copy link
Contributor

@ossdhaval ossdhaval Apr 14, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the start of the document(before the image), few lines explaining the why of this feature would be useful. Why do we have this feature? How does it help to enable token validation?

Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>
@SafinWasi SafinWasi requested a review from ossdhaval April 15, 2025 15:51
@mo-auto
Copy link
Member

mo-auto commented May 15, 2025

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

@SafinWasi SafinWasi requested a review from rmarinn May 15, 2025 15:40
@SafinWasi SafinWasi enabled auto-merge (squash) May 16, 2025 15:18
SafinWasi and others added 2 commits May 16, 2025 10:18
@SafinWasi SafinWasi merged commit 4c43f6a into main May 16, 2025
1 check passed
@SafinWasi SafinWasi deleted the docs-jans-cedarling-refactor branch May 16, 2025 15:29
rmarinn pushed a commit that referenced this pull request May 20, 2025
* docs(jans-cedarling): docs refactor for cedarling

Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>

* docs(jans-cedarling): fix indenting

Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>

* docs(jans-cedarling): rename boolean file

Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>

* fix(docs): add tags

Signed-off-by: ossdhaval <343411+ossdhaval@users.noreply.github.com>

* docs(jans-cedarling): address feedback

Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>

---------

Signed-off-by: SafinWasi <6601566+SafinWasi@users.noreply.github.com>
Signed-off-by: ossdhaval <343411+ossdhaval@users.noreply.github.com>
Co-authored-by: ossdhaval <343411+ossdhaval@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area-documentation Documentation needs to change as part of issue or PR comp-docs Touching folder /docs comp-jans-cedarling Touching folder /jans-cedarling
Projects
None yet
Development

Successfully merging this pull request may close these issues.

docs(jans-cedarling): cedarling doc refactor
6 participants