Methods and systems for performing domain-wide authentication and authorization
According to one embodiment, a method for performing domain-wide authentication and authorization in a cloud-based environment can comprise receiving, from a third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the third-party service for accessing a cloud-based storage system of the cloud-based environment. A mapping of the user of the third-party service to a user account of the cloud-based storage system can be generated and one or more tokens for the user of the third-party service can in turn be generated based on the mapping of the user of the third-party service to the user account of the cloud-based storage system. The one or more tokens can provide access to services of the cloud-based storage system. The one or more tokens can be provided to the third-party service.
1 . A method for performing domain-wide authentication and authorization in a cloud-based environment, the method comprising:
initiating, by a domain-wide authorization system, a backfill process performing domain-wide authentication and authorization for a plurality of users of a third-party service of the cloud-based environment, wherein the backfill process comprises onboarding of the plurality of users of the third-party service as users of the cloud-based environment;
receiving, by the domain-wide authorization system, from the third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the of the plurality of users of the third-party service for accessing a cloud-based storage system of the cloud-based environment through the third-party service, wherein the user of the third party service is logged into the third-party service but not the cloud-based storage system;
generating, by the domain-wide authorization system, a mapping of the user of the third-party service to a user account of the user of the third-party service on the cloud-based storage system;
generating, by the domain-wide authorization system, one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system, wherein the one or more tokens provide access to services of the cloud-based storage system; and
providing, by the domain-wide authorization system, the one or more tokens to the third-party service.
2 . The method of claim 1 , further comprising, prior to generating the mapping of the user of the third-party service to the user account of the cloud-based storage system, determining, by the domain-wide authorization system, whether the user of the third-party service is eligible for domain-wide authentication and authorization and wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system, generating the one or more tokens for the user of the third-party service, and providing the one or more tokens to the third-party service are performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.
3 . The method of claim 1 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:
receiving, by the domain-wide authorization system, from the third-party service, user information for the user of the third-party service;
searching, by the domain-wide authorization system, a set of user information of the cloud-based storage system based on the received user information for the user of the third-party service; and
determining, by the domain-wide authorization service, whether the user information for the user of the third-party service matches any user information in the set of user information of the cloud-based storage system, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user information for the user of the third-party service matches user information in the set of user information of the cloud-based storage system.
4 . The method of claim 3 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining, by the domain-wide authorization system, whether the user of the third-party service is eligible for domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.
5 . The method of claim 3 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining, by the domain-wide authorization system, whether the user of the third-party service has opted out of domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service has not opted out of domain-wide authentication and authorization.
6 . The method of claim 1 , wherein generating the one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:
receiving, by the domain-wide authorization system, from the cloud-based storage system, information indicating a scope for authorization of the user of the third-party system;
obtaining, by the domain-wide authorization system, the one or more tokens for the user of the third-party service based on the information indicating the scope for authorization of the user of the third-party system;
providing, by the domain-wide authorization system, the one or more tokens for the user of the third-party service to the third-party service; and
notifying, by the domain-wide authorization system, the user of the third-party service of authorization completion.
7 . The method of claim 1 , wherein the backfill process comprises:
adding, by the domain-wide authorization system, an initiation message for the backfill process to a backfill queue, the initiation message identifying an entity for which the backfill process is performed, wherein the user and the set of users are associated with the entity;
reading, by the domain-wide authorization system, the initiation message for the backfill process from the backfill queue;
retrieving, by the domain-wide authorization system, user information for the set of users based on the entity identified in the initiation message;
assigning, by the domain-wide authorization system, the set of users to a group of users for the backfill process;
creating, by the domain-wide authorization system, a fanout job for the group of users;
adding, by the domain-wide authorization system, the fanout job to a job queue;
reading, by the domain-wide authorization system, the fanout job from the job queue;
mapping, by the domain-wide authorization system, the set of users of the third-party service to a set of users account of the cloud-based storage system;
generating, by the domain-wide authorization system, one or more tokens for the set of users of the third-party service based on the mapping of the set of users of the third-party service to the set of users account of the cloud-based storage system;
providing, by the domain-wide authorization system, the one or more tokens for the set of users of the third-party service to the third-party service; and
notifying, by the domain-wide authorization system, the set of users of the third-party service of authorization completion.
8 . A system comprising:
a processor; and
a memory coupled with and readable by the processor and storing therein a set of instructions which, when executed by the processor, causes the processor to perform domain-wide authentication and authorization in a cloud-based environment by:
initiating a backfill process performing domain-wide authentication and authorization for a plurality of users of a third-party service of the cloud-based environment, wherein the backfill process comprises onboarding of the plurality of users of the third-party service as users of the cloud-based environment;
receiving, from the third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the of the plurality of users of the third-party service for accessing a cloud-based storage system of the cloud-based environment through the third-party service, wherein the user of the third party service is logged into the third-party service but not the cloud-based storage system;
generating a mapping of the user of the third-party service to a user account of the user of the third-party service on the cloud-based storage system;
generating one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system, wherein the one or more tokens provide access to services of the cloud-based storage system; and
providing the one or more tokens to the third-party service.
9 . The system of claim 8 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:
receiving, from the third-party service, user information for the user of the third-party service;
searching a set of user information of the cloud-based storage system based on the received user information for the user of the third-party service; and
determining whether the user information for the user of the third-party service matches any user information in the set of user information of the cloud-based storage system, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user information for the user of the third-party service matches user information in the set of user information of the cloud-based storage system.
10 . The system of claim 9 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service is eligible for domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.
11 . The system of claim 9 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service has opted out of domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service has not opted out of domain-wide authentication and authorization.
12 . The system of claim 8 , wherein generating the one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:
receiving, from the cloud-based storage system, information indicating a scope for authorization of the user of the third-party system;
obtaining the one or more tokens for the user of the third-party service based on the information indicating the scope for authorization of the user of the third-party system;
providing the one or more tokens for the user of the third-party service to the third-party service; and
notifying the user of the third-party service of authorization completion.
13 . The system of claim 8 , wherein the backfill process comprises:
adding an initiation message for the backfill process to a backfill queue, the initiation message identifying an entity for which the backfill process is performed, wherein the user and the set of users are associated with the entity;
reading the initiation message for the backfill process from the backfill queue;
retrieving user information for the set of users based on the entity identified in the initiation message;
assigning the set of users to a group of users for the backfill process;
creating a fanout job for the group of users;
adding the fanout job to a job queue;
reading the fanout job from the job queue;
mapping the set of users of the third-party service to a set of users account of the cloud-based storage system;
generating one or more tokens for the set of users of the third-party service based on the mapping of the set of users of the third-party service to the set of users account of the cloud-based storage system;
providing the one or more tokens for the set of users of the third-party service to the third-party service; and
notifying the set of users of the third-party service of authorization completion.
14 . A non-transitory, computer-readable medium comprising a set of instructions stored therein which, when executed by a processor, causes the processor to perform domain-wide authentication and authorization in a cloud-based environment by:
initiating a backfill process performing domain-wide authentication and authorization for a plurality of users of a third-party service of the cloud-based environment, wherein the backfill process comprises onboarding of the plurality of users of the third-party service as users of the cloud-based environment;
receiving, from the third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the of the plurality of users of the third-party service for accessing a cloud-based storage system of the cloud-based environment through the third-party service, wherein the user of the third party service is logged into the third-party service but not the cloud-based storage system;
generating a mapping of the user of the third-party service to a user account of the user of the third-party service on the cloud-based storage system;
generating one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system, wherein the one or more tokens provide access to services of the cloud-based storage system; and
providing the one or more tokens to the third-party service.
15 . The non-transitory, computer-readable medium of claim 14 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:
receiving, from the third-party service, user information for the user of the third-party service;
searching a set of user information of the cloud-based storage system based on the received user information for the user of the third-party service; and
determining whether the user information for the user of the third-party service matches any user information in the set of user information of the cloud-based storage system, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user information for the user of the third-party service matches user information in the set of user information of the cloud-based storage system.
16 . The non-transitory, computer-readable medium of claim 15 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service is eligible for domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.
17 . The non-transitory, computer-readable medium of claim 15 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service has opted out of domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service has not opted out of domain-wide authentication and authorization.
18 . The non-transitory, computer-readable medium of claim 14 , wherein generating the one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:
receiving, from the cloud-based storage system, information indicating a scope for authorization of the user of the third-party system;
obtaining the one or more tokens for the user of the third-party service based on the information indicating the scope for authorization of the user of the third-party system;
providing the one or more tokens for the user of the third-party service to the third-party service; and
notifying the user of the third-party service of authorization completion.
19 . The non-transitory, computer-readable medium of claim 14 , wherein the backfill process comprises:
adding an initiation message for the backfill process to a backfill queue, the initiation message identifying an entity for which the backfill process is performed, wherein the user and the set of users are associated with the entity;
reading the initiation message for the backfill process from the backfill queue;
retrieving user information for the set of users based on the entity identified in the initiation message;
assigning the set of users to a group of users for the backfill process;
creating a fanout job for the group of users;
adding the fanout job to a job queue;
reading the fanout job from the job queue;
mapping the set of users of the third-party service to a set of users account of the cloud-based storage system;
generating one or more tokens for the set of users of the third-party service based on the mapping of the set of users of the third-party service to the set of users account of the cloud-based storage system;
providing the one or more tokens for the set of users of the third-party service to the third-party service; and
notifying the set of users of the third-party service of authorization completion.