Merge pull request #14355 from jamieklassen/patch-4

[docs] complete azure outbound access requirements
This commit is contained in:
Fredrik Adelöw
2022-11-07 15:23:20 +01:00
committed by GitHub
+13 -5
View File
@@ -46,11 +46,19 @@ The Microsoft provider is a structure with three configuration keys:
- `clientSecret`: Secret, found on App Registration > Certificates & secrets
- `tenantId`: Directory (tenant) ID, found on App Registration > Overview
In order to finish signing a user in from Azure, the Backstage backend must
fetch their information from graph.microsoft.com (as seen in [this source
code](https://github.com/seanfisher/passport-microsoft/blob/0456aa9bce05579c18e77f51330176eb26373658/lib/strategy.js#L93-L95)),
so ensure that your Backstage backend has connectivity to this host.
Otherwise users may see an `Authentication failed, failed to fetch user profile` error when they attempt to log in.
## Outbound Network Access
If your environment has restrictions on outgoing access (e.g. through
firewall rules), make sure your Backstage backend has access to the following
hosts:
- `login.microsoftonline.com`, to get and exchange authorization codes and access
tokens
- `graph.microsoft.com`, to fetch user profile information (as seen
in [this source
code](https://github.com/seanfisher/passport-microsoft/blob/0456aa9bce05579c18e77f51330176eb26373658/lib/strategy.js#L93-L95)).
If this host is unreachable, users may see an `Authentication failed, failed to fetch user profile` error when they attempt to log in.
## Adding the provider to the Backstage frontend