Authorization scope management delegation
Techniques for authorization scope management delegation are described. An administrative user provides access scope information to be utilized for one or more users of a cloud provider network. The access scope information is utilized by an identity service of the cloud provider network in generating access tokens that can be utilized when accessing resources managed or hosted by services of the cloud provider network, whereby one or more services can use the scope information that was pre-configured by the administrative user during the execution of operations for individual users without the users needing to provide or confirm the scopes.
1 . A computer-implemented method comprising:
receiving, at an identity service of a cloud provider network, one or more requests originated by an administrative user account to define pre-approved OAuth access scope information for at least one individual user account of an organization, the OAuth access scope information specifying, for each of a plurality of applications within the cloud provider network that can be invoked in a call chain, one or more types of permitted actions or resources accessible by the individual user account;
storing the OAuth access scope information in association with the individual user account;
receiving, at a first application, a request to invoke one or more functionalities or operations, wherein the request was originated on behalf of the individual user account and includes an access token generated by an identity provider, wherein the functionalities or operations involve actions or resource accesses governed by the OAuth access scope information based;
determining, by the first application, that a first action, operation, or data access to be performed by the first application for the request is authorized based at least in part on the access token and the OAuth access scope information for the individual user account;
invoking, by the first application, a second application in the call chain as part of servicing the request; and
determining, by the second application, that a second action, operation, or data access to be performed by the second application for the request is authorized based at least on the OAuth access scope information for the individual user account,
wherein the individual user account is permitted to access resources and perform actions across the plurality of applications in the call chain without being required to individually authorize OAuth scopes for each application at runtime.
2 . The computer-implemented method of claim 1 , wherein the OAuth access scope information is provided for a group of users within the organization, and wherein determining that the request to access the resource is authorized comprises:
determining, by the first application via an interaction with the identity service, that the individual user account is a member of the group; and
determining, by the first application, that the group has been granted privileges allowing the first action, operation, or data access.
3 . A computer-implemented method comprising:
receiving, at an identity service of a cloud provider network, one or more requests originated by an administrative user account to define OAuth access scope information for at least one individual user account of an organization, the OAuth access scope information specifying, for at least a first application within the cloud provider network, one or more types of permitted actions or resources accessible by the individual user account;
storing the OAuth access scope information in association with the individual user account;
receiving, at the first application, a request to invoke one or more functionalities or operations that was originated on behalf of the individual user account, wherein the request includes an access token generated by an identity provider based on an authorization of the individual user account;
determining, by the first application, that an action, operation, or data access to be performed by the first application for the request is authorized based at least in part on the access token and the OAuth access scope information; and
executing, by the first application, the action, operation, or data access.
4 . The computer-implemented method of claim 3 , wherein the OAuth access scope information specifies permitted actions or resources for a group of users, wherein determining that the action, operation, or data access is authorized comprises:
determining, by the first application via an interaction with the identity service, that the individual user account is a member of the group; and
determining, by the first application, that the group has been granted privileges matching the permitted actions or resources.
5 . The computer-implemented method of claim 3 , wherein the OAuth access scope information indicates that the individual user account is allowed to create, read, write, or delete a resource.
6 . The computer-implemented method of claim 3 , wherein the method further comprises:
receiving, at a second application from the first application, a second request to invoke one or more functionalities or operations as part of the first application performing operations to service the request; and
determining that a second action, operation, or data access to be performed by the second application for the second request is authorized based at least in part on the OAuth access scope information for the individual user account.
7 . The computer-implemented method of claim 3 , wherein the administrative user account is associated with an organization and the individual user account is one of a plurality of user accounts of employees of the organization.
8 . The computer-implemented method of claim 3 , wherein the access token was obtained by a computing device utilized by a user associated with the individual user account as part of accessing a second application, wherein the second application transmitted the request to invoke one or more functionalities or operations on behalf of the individual user account.
9 . The computer-implemented method of claim 8 , wherein the access token was obtained by the computing device as part of a sign-on process, wherein the sign-on process does not include the user consenting or providing any access scope information.
10 . The computer-implemented method of claim 3 , wherein the first application comprises a service within the cloud provider network.
11 . The computer-implemented method of claim 3 , wherein the access token is an OAuth compliant token.
12 . The computer-implemented method of claim 8 , further comprising:
recording, by a monitoring service of the cloud provider network, an activity event indicative of the action, operation, or data access, the activity event including an identifier of the individual user account even though the action, operation, or data access occurred responsive to the request transmitted by the second application.
13 . A system comprising:
a first one or more computing devices to implement an identity service in a multi-tenant cloud provider network, the identity service including instructions that upon execution cause the identity service to:
receive one or more requests originated by an administrative user account to define OAuth access scope information for at least one individual user account of an organization, the OAuth access scope information specifying, for at least a first application within the cloud provider network, one or more types of permitted actions or resources accessible by the individual user account, and
store the OAuth access scope information in association with the individual user account; and
a second one or more computing devices to implement the first application in the multi-tenant cloud provider network, the first application including instructions that upon execution cause the first application to:
receive a request to invoke one or more functionalities or operations that was originated on behalf of the individual user account, wherein the request includes an access token generated by an identity provider based on an authorization of the individual user account,
determine that an action, operation, or data access to be performed by the first application for the request is authorized based at least in part on the access token and the OAuth access scope information, and
execute the action, operation, or data access.
14 . The system of claim 13 , wherein the OAuth access scope information specifies permitted actions or resources for a group of users, wherein to determine that action, operation, or data access the request to access the resource is authorized comprises:
determining, via an interaction with the identity service, that the individual user account is a member of the group; and
determining that the group has been granted privileges matching the permitted actions or resources.
15 . The system of claim 13 , wherein the access token was obtained by a computing device utilized by a user associated with the individual user account as part of accessing a second application, wherein the second application transmitted the request to invoke one or more functionalities or operations on behalf of the individual user account.
16 . The system of claim 15 , wherein the access token was obtained by the computing device as part of a sign-on process, wherein the sign-on process does not include the user consenting or providing any access scope information.
17 . The system of claim 13 , wherein the OAuth access scope information indicates that the individual user account is allowed to create, read, write, or delete a resource.