Skip to content

Context Authorization

Represents a fully authorized connection of a user.

There are more specialized variants of the authorization available, based on which authorization type was used:

Variant Authorization
Bifröst Bifröst delegation
Htpasswd Htpasswd
Local Local
OpenID Connect (OIDC) OpenID Connect (OIDC)
Simple Simple
None None

Bifröst

Is the result of a successful certificate-based delegation from another Bifröst authorization. The common authorization remote remains the immediately connected SSH peer; use origin for the unchanged original identity.

Properties

origin

object

The original user, host and authorizationKind from the first Bifröst instance.

peer

object

The final, immediately verified hop. It contains the CA and subject-key fingerprints, serial, key ID, upstream session ID and flow, authorization kind, audience, target user, validity boundaries, and effective capability booleans.

hops

list of objects

The complete normalized delegation path. Each object has the same fields as peer. The list has at most eight entries.

policy

object

The effective ptyAllowed, portForwardingAllowed and agentForwardingAllowed values after all hops.

Passwords, tokens, unrestricted identity-provider claims and arbitrary environment maps are never included in this context.

Htpasswd

Is the result of a successful authorization via Htpasswd authorization.

Properties

user

string

Holds the user(name) of the successfully authorized user.

Local

Is the result of a successful authorization via Local authorization.

Properties

user

Holds the successfully authorized user.

OpenID Connect (OIDC)

Is the result of a successful authorization via OpenID Connect (OIDC) authorization.

Properties

token

Holds the token information (like access token, expiry, ...) of the authorized user.

idToken

Can hold the ID Token of the authorized user, if configured and available.

userInfo

Can hold the UserInfo of the authorized user, if configured and available.

Simple

Is the result of a successful authorization via Simple authorization.

Properties

entry

Holds a representation of the authorized record of Simple authorization entries.

None

Is the result of a successful authorization via None authorization.

Properties

None.