Setup OIDC conformant Auth0 config#5395
Merged
Merged
Conversation
Contributor
[backport] ReminderPlease consider backporting to the following branches:
And your PR is currently against base branch: main. Note: Any PR comment containing [backport] will be considered for auto-backporting upon merge, |
rautenrieth-da
approved these changes
May 6, 2026
Contributor
rautenrieth-da
left a comment
There was a problem hiding this comment.
Looks reasonable to me.
Signed-off-by: Paweł Perek <[email protected]>
Signed-off-by: Paweł Perek <[email protected]>
79fc8da to
61980ac
Compare
martinflorian-da
added a commit
that referenced
this pull request
May 8, 2026
It breaks infra deployments: DACH-NY/cn-test-failures#8318 (comment) [static] This reverts commit 4e779e8.
7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes https://github.com/DACH-NY/canton-network-internal/issues/4513
This PR configures Auth0 refresh tokens in accordance with the best practices outlined in RFC 9700 (OAuth 2.0 Security Best Current Practice) §4.14:
Presentations of points 1 and 2:
rotation.mp4
Pull Request Checklist
Cluster Testing
/cluster_teston this PR to request it, and ping someone with access to the DA-internal system to approve it./hdm_teston this PR to request it, and ping someone with access to the DA-internal system to approve it./lsu_teston this PR to request it, and ping someone with access to the DA-internal system to approve it.PR Guidelines
Fixes #n, and mention issues worked on using#nMerge Guidelines