Skip to content

IAP for External Identities - Tenant Login UI Configuration

Notifications You must be signed in to change notification settings

maucaro/tenant-login-ui-config

Repository files navigation

IAP for External Identities - Tenant Login UI Configuration

This project implements a Google Cloud Function using the Functions Framework for Node.js to update tenant login UI configuration programmatically as described here.

This function is meant to be invoked as part of the automated process that provisions and deprovisions tenants.

The following JSON data structure must be included in the POST payload:

{
    "operation":"add|delete",
    "tenantId":"tenant1-624h4", 
    "tenantUiConfig":{...}
}

Data structure notes:

  • operation must be either "add" or "delete"
  • tenantId must conform to the following regular expression: /[a-z][a-z0-9-]{8,14}[a-z0-9]/
  • tenantUiConfig conforms to ExtendedTenantUiConfig interface; additional information can be found here

Environment variable:

  • AUTH_HOST (required): the target authentication host

Cloud Function notes:

  • The service account assigned to Cloud Function requires the https://www.googleapis.com/auth/devstorage.read_write scope as described here.
  • In order to avoid a possible race condition where one update overwrites another, it's recommended that requests do not run concurrently. In Cloud Functions this can be accomplished by setting the "max-instances" option to 1.

About

IAP for External Identities - Tenant Login UI Configuration

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published