Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: whitelist idtech.no domains #1759

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

taraldr
Copy link

@taraldr taraldr commented Apr 29, 2024

Context:

These domains (*.idtech.no) host test environments for my employer and are visited by integrators, not end users at large.

Possible reasons we were flagged to begin with:

We (BankID) use CSP policies to enforce secure environments for our end users as breaches could lead to losing their life savings, seeing as BankID is accepted as the login provided for all Norwegian banks.

We strictly adhere to GDPR.

Some of these services are OIDC implementation, which can involve chaining multiple redirects in order to transport authentication codes via URL though multiple layers of OIDC flows. These redirect chains may be interpreted by some as tracking, but we do not track our users other than what's described in our privacy policy in order to protect their digital identity, which all banks and all end users who use our product have explicitly agreed to.

For more info on BankID, see https://bankid.no/en/what-is-bankid

Closes #1758

@taraldr
Copy link
Author

taraldr commented May 3, 2024

@badmojr, are you available to help expedite this please? 🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Whitelist idtech.no
1 participant