awscli-login icon indicating copy to clipboard operation
awscli-login copied to clipboard

Need means to login into IdP without requesting STS credentials

Open ddriddle opened this issue 7 years ago • 8 comments

For our internal testing needs it would be useful to have a means to login into the IdP and get a cookie, but not request an STS credential. Add the following flag to support this operation:

$ aws login --idp-login-only

ddriddle avatar Dec 17 '18 16:12 ddriddle

@JonRoma or @cmaturi - Is there still interest in this feature to assist with testing? Thanks!

edthedev avatar Dec 02 '21 20:12 edthedev

For my part, I don't remember this at all, and I can't say I've ever thought about this.

JonRoma avatar Dec 02 '21 20:12 JonRoma

@JonRoma this was something that Scrum Team D was interested in. I think they may have found another solution. Not sure. I would ping Maiko or John Gordman but I don't seem able to here.

ddriddle avatar Dec 02 '21 20:12 ddriddle

I haven't got a clue what they want.

JonRoma avatar Dec 02 '21 22:12 JonRoma

You're going to have a hard time hitting the IdP without telling it that the user is logging into a specific SP. It could be a fake SP, but there still has to be a destination, or the IdP will just error out. You, of course, don't have to do anything with the response; you can just drop it on the floor. Or you can parse it and display debugging info without sending it on to the SP (AWS, in this case). But there still has to be na SP involved.

kwessel avatar Dec 02 '21 23:12 kwessel

@kwessel from what I remember from three years ago is that we wanted the cookie generated by the login to the IdP but did not really need the credentials from AWS. So yes, we would have to specify an SP, in this case AWS, but we do not have to request a token from AWS which would be the point of the flag.

ddriddle avatar Dec 02 '21 23:12 ddriddle

@ddriddle, I would check with them directly to see if this is still a need. I haven't heard a peep about it, so I suspect it may have been a fleeting interest that has fleeted into the past.

JonRoma avatar Dec 04 '21 01:12 JonRoma

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 14 days.

github-actions[bot] avatar Mar 28 '24 13:03 github-actions[bot]