Skip to content

Conversation

@louischan-oursky
Copy link
Contributor

ref DEV-2767

@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch 2 times, most recently from 671096d to a7b3aa1 Compare June 4, 2025 07:26
@louischan-oursky louischan-oursky changed the title Add research result on Auth0 organization Research on organizations Jun 5, 2025
@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch 4 times, most recently from 44e35af to 2a99b68 Compare June 9, 2025 08:34
@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch 2 times, most recently from ca1f9a3 to 59fc935 Compare June 17, 2025 07:53
@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch 2 times, most recently from 60efaf6 to 8b120e8 Compare July 10, 2025 07:29
@louischan-oursky
Copy link
Contributor Author

Note to my self: research how does a SPA support multiple login endpoints, with each login endpoints for a particular organization.

@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch 2 times, most recently from f641b23 to 931a309 Compare July 22, 2025 08:24

It may be tempting to move the select-organization step right after the User is identified.
But doing that before the User is authenticated may leak information.
So it should not be done.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tung suggests

  1. For password policy, use the strictest settings in enter-password
  2. For MFA, only require MFA when the org requries it.

4. The idea of computing the most strict password policies / MFA requirements, and then determine which a sign-in is needed it also very hard to document.
If it is hard to document, then it is probably that the developer will have a hard time using it.

5. GitHub allows the user to be member of multiple organizations. During sign-in, the user is not prompted to select an organization. If one of the organization the user belongs to require 2FA, then the user is required to have 2FA. Even Auth0 cannot model this use-case without resorting to Auth0 post-login actions.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Allow session to be created without organization. This behavior is controlled by a query.

@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch 6 times, most recently from 495c553 to 0b84d34 Compare July 31, 2025 08:32
@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch 2 times, most recently from 33fda54 to d306713 Compare August 5, 2025 03:48
@louischan-oursky louischan-oursky force-pushed the dev-2767-organization-research branch from d306713 to 0335a16 Compare August 6, 2025 06:39
@louischan-oursky
Copy link
Contributor Author

On 2025-08-19, Ben posted a message on Basecamp https://3.basecamp.com/3096882/buckets/11477446/messages/8976557090

SCIM

The developer may want to use SCIM to sync an external user pool via SCIM to an organization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants