auth0-deploy-cli icon indicating copy to clipboard operation
auth0-deploy-cli copied to clipboard

Missing support for Bot Detection in attackProtection setttings

Open jeremysimmons opened this issue 2 years ago • 11 comments

Description

Missing JSON file for configuring bot detection feature

Reproduction

Detail the steps taken to reproduce this error, what was expected, and whether this issue can be reproduced consistently or if it is intermittent.

npm i -g auth0-deploy-cli
a0deploy export --config_file config.json --format directory --output_folder tenant

reference https://auth0.com/docs/deploy-monitor/deploy-cli-tool/install-and-configure-the-deploy-cli-tool

a0deploy Outputs files in tennant/attack-protection

  • breached-password-detection.json
  • brute-force-protection.json
  • suspicious-ip-throttling.json

Missing a file for Bot Detection feature, expected utility to include, but suspect it is not, as it's not listed in the management api docs. https://auth0.com/docs/api/management/v2#!/Attack_Protection/get_breached_password_detection https://auth0.com/docs/api/management/v2#!/Attack_Protection/get_brute_force_protection https://auth0.com/docs/api/management/v2#!/Attack_Protection/get_suspicious_ip_throttling

Environment

auth0-deploy-cli 7.3.0 node v16.17.0 Microsoft Windows [Version 10.0.22000.856]

jeremysimmons avatar Sep 08 '22 23:09 jeremysimmons

As I think you've deduced, while Bot Detection is nestled under attack protection in the dashboard, it is not available in the management API yet. The appropriate teams are aware and we expect to have that endpoint established around EOY22-BOY23. At which point we'd immediately integrated into the Deploy CLI. Related: #546

willvedd avatar Sep 09 '22 11:09 willvedd

Thank you for the prompt reply @willvedd .

Please emphasize to management how releasing a feature in the UI that does not have a matching API is detriment for teams that have adopted devops and code-as-configuration.

We look forward to this being supported in the future!

Sadly, Related: https://github.com/auth0/auth0-deploy-cli/issues/377 was opened 1 year ago...

jeremysimmons avatar Sep 09 '22 12:09 jeremysimmons

THe same here!

aldodfm avatar Nov 24 '22 12:11 aldodfm

Following-up again on this. We understand that this is a highly-desired feature for folks. Unfortunately, we're still blocked on this as Auth0 Management API does not support bot detection. There has been some motion internally to get this out, but I'm unable to provide an estimated delivery date for this.

willvedd avatar Feb 01 '23 12:02 willvedd

@willvedd thanks for updating the community on the status.

jeremysimmons avatar Feb 01 '23 15:02 jeremysimmons

Any update on this? It is a year since this was last commented upon. Even an estimated date would be helpful.

michael-mcguinness avatar Jan 29 '24 16:01 michael-mcguinness

I am also looking for update on this same as Michael. Is there an ETA when we can see this available thru deploy-cli

kapil-gulati avatar Feb 21 '24 21:02 kapil-gulati

Any updates?

bku-bezell avatar Jul 02 '24 15:07 bku-bezell