Context Authorization
Represents a fully authorized connection of a user.
There are more specialized variants of the authorization available, based on which authorization type was used:
| Variant | Authorization |
|---|---|
| Bifröst | Bifröst delegation |
| Htpasswd | Htpasswd |
| Local | Local |
| OpenID Connect (OIDC) | OpenID Connect (OIDC) |
| Simple | Simple |
| None | None |
Bifröst
Is the result of a successful certificate-based delegation from another Bifröst authorization. The common authorization remote remains the immediately connected SSH peer; use origin for the unchanged original identity.
Properties
origin
object
The original user, host and authorizationKind from the first Bifröst instance.
peer
object
The final, immediately verified hop. It contains the CA and subject-key fingerprints, serial, key ID, upstream session ID and flow, authorization kind, audience, target user, validity boundaries, and effective capability booleans.
hops
list of objects
The complete normalized delegation path. Each object has the same fields as peer. The list has at most eight entries.
policy
object
The effective ptyAllowed, portForwardingAllowed and agentForwardingAllowed values after all hops.
Passwords, tokens, unrestricted identity-provider claims and arbitrary environment maps are never included in this context.
Htpasswd
Is the result of a successful authorization via Htpasswd authorization.
Properties
user
string
Holds the user(name) of the successfully authorized user.
Local
Is the result of a successful authorization via Local authorization.
Properties
user
Holds the successfully authorized user.
OpenID Connect (OIDC)
Is the result of a successful authorization via OpenID Connect (OIDC) authorization.
Properties
token
Holds the token information (like access token, expiry, ...) of the authorized user.
idToken
Can hold the ID Token of the authorized user, if configured and available.
userInfo
Can hold the UserInfo of the authorized user, if configured and available.
Simple
Is the result of a successful authorization via Simple authorization.
Properties
entry
Holds a representation of the authorized record of Simple authorization entries.
None
Is the result of a successful authorization via None authorization.
Properties
None.