terraform-provider-auth0 icon indicating copy to clipboard operation
terraform-provider-auth0 copied to clipboard

Configuration of Bot Detection/ReCAPTCHA

Open Moggers opened this issue 3 years ago • 15 comments

Describe the problem you'd like to have solved

Under Security -> Attack Prevention -> Bot Detection of the Auth0 management UI there is a section for enabling ReCAPTCHAv2 in the universal login. Currently there doesn't seem to be a way to configure this via the terraform module.

Describe the ideal solution

Being able to enable ReCAPTCHA and specify keys via terraform.

Alternatives and current workarounds

Currently a manually process.

Moggers avatar Mar 04 '22 07:03 Moggers

Hey @Moggers, thanks for opening this issue. Unfortunately we're unable to add this feature yet due to the endpoint on the management API missing. It currently covers only the following: https://auth0.com/docs/api/management/v2#!/Attack_Protection/get_breached_password_detection.

Will update this whenever this is available.

sergiught avatar Mar 04 '22 12:03 sergiught

hi @sergiught is there any place I can track the addition of this endpoint within management API? It's something I'd like to be able to accomplish as well. Thanks!

zachfeld avatar Aug 31 '22 20:08 zachfeld

This is the biggest gap we're facing currently. Not just configuring the captcha but also the risk assessment logs, IP allow list, etc.

Aaronius avatar Jan 29 '23 00:01 Aaronius

Is this still an issue:

https://auth0.com/docs/api/management/v2#!/Attack_Protection/patch_suspicious_ip_throttling

davedash avatar Apr 20 '23 18:04 davedash

Is this still an issue:

https://auth0.com/docs/api/management/v2#!/Attack_Protection/patch_suspicious_ip_throttling

@davedash Yes, suspicious IP throttling is not the same as bot detection. This feature is still blocked by a lack of an API endpoint. Rest assured, we're keen on delivering this feature as soon as we're able!

willvedd avatar Apr 20 '23 18:04 willvedd

@willvedd Lol, I was so excited, and as I was editing my terraform config, I realized the same thing. Thanks.

davedash avatar Apr 20 '23 19:04 davedash

Any updates on this one?

mikalai-t avatar Jul 25 '23 08:07 mikalai-t

Hey folks, unfortunately no updates yet on this. We are still waiting for the endpoints to get added to the Management API. As soon as that happens we'll immediately add support within our tooling. We'll be sure to post an update in this issue when that happens. Appreciate everyones patience! 🙏🏻

sergiught avatar Jul 25 '23 14:07 sergiught

Are there any further updates/timelines on this one?

EQnews avatar Oct 31 '23 11:10 EQnews

Any updates on this one? Its been almost 2 years. Thats a decent lag time for a. Terraform provider.

cbeardsmore avatar Feb 04 '24 14:02 cbeardsmore

Hi - is there any update on this? I was told that Terraform capability depends on the release of 'Bot Detection Public API' which is on the roadmap planned for 2024 Q1 (FEB - APR). Is this on track?

EQnews avatar Mar 05 '24 17:03 EQnews

@EQnews our Auth0 customer rep told us this week that it's now scheduled for H2 2024 😬

luislew avatar Mar 28 '24 22:03 luislew

Hello, can we please get specific dates for this release?

kxs-mdoyon avatar Apr 23 '24 19:04 kxs-mdoyon

our Auth0 customer rep told us this week that it's now scheduled for H2 2024 😬

Ran into this issue as well, it's a little annoying. Is anybody from Auth0 able to confirm this?

igobl avatar May 31 '24 09:05 igobl