FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login
    1. Home
    2. dan
    • Profile
    • Following 0
    • Followers 10
    • Topics 686
    • Posts 2,736
    • Best 172
    • Controversial 0
    • Groups 4

    dan

    @dan

    Principal Product Engineer at FusionAuth.

    Enjoys ruby, java, php. Finds golang challenging.

    Likes the authorization code grant, automation, stories and clear documentation.

    Hiker, camper, gardener. Used to have chickens, now just tomatos.

    184
    Reputation
    206
    Profile views
    2.7k
    Posts
    10
    Followers
    0
    Following
    Joined Last Online
    Website fusionauth.io Location Colorado, USA

    dan Unfollow Follow
    FAQ Posters Staff Power User administrators

    Best posts made by dan

    • Is there a way to update user data in the UI?

      I'd like to update the user data object in the UI. I know I can do it via the API: https://fusionauth.io/docs/v1/tech/apis/users

      posted in Q&A user-data user-api from-slack faq
      danD
      dan
    • Seeking product feedback on FusionAuth's logging

      FusionAuth's logging isn't one system, it's three: system/app logs on disk or stdout (monitor docs, troubleshooting), audit logs for admin UI changes via webhooks or the Audit Log API, and event logs for debugging surfaced through webhooks or the Event Log API.

      None of them ship anywhere on their own, so if you want this in Datadog or Splunk, you're polling the API or writing your own ingester (by following doc, but still).

      We're looking for feedback on this.

      What's great about FusionAuth's logging, and what sucks or needs to be improved?

      posted in Announcements
      danD
      dan
    • FusionAuth releases SimplePassβ„’

      https://fusionauth.io/blog/2021/04/01/fusionauth-introduces-simplepass/

      posted in Blogs
      danD
      dan
    • RE: Block authentication until user is verified?

      Is modifying the JWT via a lambda equivalent to accessing the verified property of the user profile?

      Within a lambda, you have access to the user and registration properties. So you'd pull the verified property from wherever you wanted and put it into the JWT as a custom claim. Here's a blog post about how that might work.

      So yes, it is the same data. It's the tradeoff between a bigger JWT and having to make the additional call from your API.

      Don't forget that the JWT will live for a while, so if this sequence happens and you use the JWT, you might have a user with a verified email prevented from using the API.

      1. user registers
      2. JWT issued, with verified set to false because the user isn't verified.
      3. User verifies their email
      4. User visits API, but is denied because the JWT has stale data.

      I don't know timelines and how long your JWTs live for, but this is something to consider. Does that answer your question?

      posted in Q&A
      danD
      dan
    • RE: Trouble getting the user object post login

      OK, we just released 1.18.8 and that is the version you want to use:

      In requirements.txt:

      fusionauth-client==1.18.8
      

      And then this is the call you want to make (with client_id before redirect_uri) :

       resp = client.exchange_o_auth_code_for_access_token(request.args.get("code"), client_id, "http://localhost:5000/oauth-callback", client_secret)
      
      posted in Q&A
      danD
      dan
    • Can I configure the inactivity timeout of the FusionAuth Session cookie?

      I have a quick question about FusionAuth and configuring the inactivity timeout of the session cookie it creates. Specifically... Is it possible?

      posted in Q&A from-slack cookies sessions inactivity faq
      danD
      dan
    • RE: I want to send email from my docker image

      I end up using a docker image of mailcatcher.

      I use the default docker-compose.yml, but use this docker-compose.override.yml:

      version: '3'
      
      services:
        mailcatcher:
          image: yappabe/mailcatcher
          ports:
            - "1025:1025"
            - "1080:1080"
          networks:
            - mailcatcher
      
        search:
          image: docker.elastic.co/elasticsearch/elasticsearch:7.8.1
          environment:
            cluster.name: fusionauth
            bootstrap.memory_lock: "true"
            discovery.type: single-node
            FUSIONAUTH_SEARCH_MEMORY: ${FUSIONAUTH_SEARCH_MEMORY}
            ES_JAVA_OPTS: ${ES_JAVA_OPTS}
          # Un-comment to access the search service directly
          # ports:
          #  - 9200:9200
          #  - 9300:9300
          networks:
            - search
          restart: unless-stopped
          ulimits:
            memlock:
              soft: -1
              hard: -1
          volumes:
            - es_data:/usr/share/elasticsearch/data
      
        fusionauth:
          depends_on:
            - search
            - mailcatcher
          environment:
            SEARCH_SERVERS: http://search:9200
            SEARCH_TYPE: elasticsearch
          networks:
            - mailcatcher
            - search
      
      networks:
        search:
          driver: bridge
        mailcatcher:
          driver: bridge
      
      volumes:
        es_data:
      

      Then I configure the SMTP settings to use the hostname mailcatcher and the port 1025. I can then send email and view it in the mailcatcher interface, at localhost:1080.

      Here's the relevant dockerfile: https://github.com/yappabe/docker-mailcatcher/blob/master/Dockerfile

      Here's more about mailcatcher: https://mailcatcher.me/

      posted in Q&A
      danD
      dan
    • RE: Error loading mysql backup

      I haven't seen that before.

      Does this happen in your customized version of FusionAuth (where you've added a few applications and users) or the default version?

      From looking at the mysqldump man page, maybe try --hex-blob ?

      You could try loading the schema from the .sql files ( https://fusionauth.io/direct-download/ ) and loading the data separately (that is, exporting with --no-create-info ). Again, that's a wild guess, not sure what the issue is, but some more investigation seems to make sense.

      posted in Q&A
      danD
      dan
    • Can you run FusionAuth in kubernetes?

      Can you run FusionAuth in Kubernetes?

      posted in Q&A kubernetes runtimes faq
      danD
      dan
    • RE: Having an issue with nginx in front of FusionAuth

      Ah, the answer is that Nginx defaults to HTTP/1.0 and if you are on a recent version of FusionAuth, this protocol is not supported by our HTTP server (HTTP 1.1 was, after all, released in 1997 πŸ™‚ ).

      The remedy is to update your Nginx configuration to use a later protocol with this change:

      proxy_http_version 1.1;
      

      Hope that helps.

      posted in Q&A
      danD
      dan

    Latest posts made by dan

    • RE: Slack-style multi-tenant login: resolve the tenant, then send (or fake) a passwordless code

      Both entry points, and especially the anti-enumeration behavior on the known-tenant path, are best built by calling FusionAuth's passwordless APIs directly from your own UI rather than relying on the hosted login pages. Here's more on the difference.

      Using the API is the only way to get full control over what the UI shows on a failure.

      Known-tenant entry (acme.ourapp.com)

      • Maintain your own slug/domain β†’ tenantId table (outside FusionAuth), populated when you provision each tenant via the Tenant API. FusionAuth has no built-in hostname-to-tenant mapping. You can learn more in the multi-tenant guide.
      • At request time, resolve the subdomain to a tenantId from that table (outside FusionAuth). If nothing matches, show "Workspace not found" β€” this never touches FusionAuth.
      • Build your own "enter your email" screen for this workspace (not FusionAuth's hosted page β€” you need to control what's shown on failure, which the hosted page won't let you do).
      • When the user submits an email, your backend calls /api/passwordless/start with that tenantId + your Universal Application id + the email as loginId. Universal Application docs here.
      • Branch on the response, entirely inside your backend:
        • 200, code sent β†’ hang onto the returned code value, respond to your frontend with a generic "we sent you a code" message, and show your own "enter the code" screen.
        • 404, no user found β†’ this is the real signal Slack is hiding. FusionAuth returns a 404 with an empty body when no user matches the tenant. Instead of surfacing that: send your own "no account with this email in this workspace" notice through your own transactional email provider (outside FusionAuth or using the send email API), then respond to your frontend with the exact same "we sent you a code" message. Show the identical "enter the code" screen either way.
      • Completing the challenge:
        • Real branch: verify the code the user types via /api/passwordless/login (tenantId + code), which returns tokens; pair this with the Hosted Backend / BFF if it's a SPA. Alternatively, redirect the browser to /oauth2/passwordless/{code}?tenantId=<tenantId>&client_id=<id> and let FusionAuth's hosted page take over the code-entry step. This is the URL FusionAuth's own passwordless email template constructs for the "click to log in" link, so redirecting there yourself just skips the email round-trip.
        • Fake branch: there is no FusionAuth code to hand off, so there's nothing to redirect to on FusionAuth's hosted domain β€” you have to own the "enter code" screen yourself here. Whatever the user types, respond with the same generic "invalid or expired code" error you'd give a real wrong code; never a distinct message. If you're using the hosted-page redirect for the real branch, don't try to fake that redirect for this branch β€” just render your own equivalent screen and always reject, rather than attempting a look-alike hosted destination.
        • Pad the fake branch's response time to roughly match a real Start call, so the two paths don't diverge on timing, which would leak the same thing you're hiding in the UI.

      Generic entry (ourapp.com/login)

      • Call /api/user/search with a global (not tenant-scoped) API key and no tenantId filter, searching by the submitted email. Each matching User record already includes its own tenantId, so this single call tells you every workspace the email belongs to. This pattern (global key, /api/user/search?queryString=<email>, results include per-tenant matches) is answered on the forum. Keep the key server-side only.
        • If you'd rather not run a global-key search on every anonymous request (latency, or wanting the key confined to a webhook receiver instead of a public endpoint), you can maintain your own email β†’ tenantId[] table fed by FusionAuth's user.create / user.update / user.delete webhooks instead. Docs at https://fusionauth.io/docs/extend/events-and-webhooks/. Either is fine β€” this is a trade-off, not a hard requirement.
      • Branch on the result (outside FusionAuth):
        • No match β†’ "No account found," stop there.
        • One match β†’ continue with that tenant.
        • Multiple matches β†’ show a workspace picker, then continue with the chosen one. This is currently functionality you have to build yourself, though there is an open issue.
      • Once a tenant is resolved, it's the same steps as section 1 from "build your own enter-email screen" onward β€” including the fake-challenge branch, if you want the same anti-enumeration behavior here too (Slack's generic "find your workspaces" entry also avoids confirming or denying a match directly, for the same reason).

      A few things worth flagging

      • FusionAuth users are tenant-scoped records β€” the same person needs a separate User object per workspace they belong to.
      • API key scope matters: the cross-tenant search in section 2 needs a global key; the tenant-specific calls in section 1 can safely use a tenant-scoped key. [Docs](Docs at https://fusionauth.io/docs/apis/api-keys).
      • The SSO session cookie isn't tenant-aware across hostnames β€” FusionAuth doesn't currently support true multi-tenant SSO through the hosted pages, so the user behavior when switching tenants requires another login. Always pass tenantId explicitly on every call.
      • Passwordless API reference for the exact Start/Login request and response shapes:
      posted in Q&A
      danD
      dan
    • Slack-style multi-tenant login: resolve the tenant, then send (or fake) a passwordless code

      We're building a multi-tenant app where each customer is a FusionAuth tenant, similar to how Slack has one "workspace" per customer. We'd like two entry points, like Slack has:

      • A known-tenant URL (acme.ourapp.com) that takes returning users straight to their workspace's login.
      • A generic entry point (ourapp.com/login) where someone just types an email β€” if it doesn't match any tenant, show "No account found"; if it does, send them a one-time code.

      We'd also like to match Slack's exact behavior on the known-tenant URL: even if the email typed in isn't a member of that workspace, still show the same "enter your code" challenge screen. The "no account" information should only ever reach the person by email, never through the UI β€” that's what lets someone try a few email addresses if they forget which one they used for a given workspace.

      What's the current best practice for doing this with FusionAuth?

      posted in Q&A slack magic link multi-tenant
      danD
      dan
    • Seeking product feedback on FusionAuth's logging

      FusionAuth's logging isn't one system, it's three: system/app logs on disk or stdout (monitor docs, troubleshooting), audit logs for admin UI changes via webhooks or the Audit Log API, and event logs for debugging surfaced through webhooks or the Event Log API.

      None of them ship anywhere on their own, so if you want this in Datadog or Splunk, you're polling the API or writing your own ingester (by following doc, but still).

      We're looking for feedback on this.

      What's great about FusionAuth's logging, and what sucks or needs to be improved?

      posted in Announcements
      danD
      dan
    • RE: What are the use cases for the user.data.email field?

      It is useful in a few scenarios.

      • When you have users that share an email address, but are in the same tenant and have distinct accounts. FusionAuth enforces uniqueness on user.email per-tenant.
      • When your users have a username (such as an account number) as a main unique identifier, but need self-service account recovery.
      • When you have duplicate email addresses in a legacy system and are migrating them to FusionAuth, whether they point to the same account or not. You can move the users over and address email updates or account merges later.

      Not all email related functionality is available when using user.data.email, but common workflows like forgot password are.

      posted in Q&A
      danD
      dan
    • What are the use cases for the user.data.email field?

      I see the user.data.email field is used when it is present and user.email is not present. From the doc:

      This field will be used as the email address if no user.email field is found. This field may be modified by advanced registration forms or the API. Setting this value to another account's email address allows that account to, in some cases, access information about this user.

      What are the use cases for that field?

      posted in Q&A
      danD
      dan
    • RE: What are FusionAuth entities good for?

      Entities are one of the most flexible parts of FusionAuth and can be used to represent links and/or permissions between domain objects and users.

      Entity types are like classes in an object-oriented programming language, which define the permissions that an entity can have.

      Entities are similar to objects, in that they are an instantiation of an entity type. No behavior though, and no inheritance.

      Entities are connected to users and other entities via grants. You can think of this setting up a directed permission graph that can be traced.

      0 to N permissions are attached to each grant.

      There are three major uses for entities:

      • the client credentials grant (agentic, machine to machine or service account authentication)
      • building limited fine grain authentication (FGA-ish) systems that don't need full ReBAC, but do want to use a permission graph or dynamically add and remove permissions
      • modelling permissions on something you don't log into

      A few notes about entities:

      • you'll want to get familiar with the API or the client libraries; entities are managed in code. Both in creating the graph and reading it from your application.
      • each entity has a data field which can handle arbitrary JSON and is searchable
      • the graph can be cyclic if you make bidirectional grants between entities. Users cannot accept grants, they can only be granted permissions to entities.
      • if you need full ReBAC or ABAC, you want FusionAuth FGA. More functionality, including automatic relationship graph traversal. The downside is you have to sync data and run a separate service.
      posted in Q&A
      danD
      dan
    • What are FusionAuth entities good for?

      I'm curious about entities. What are they good for?

      posted in Q&A entities
      danD
      dan
    • RE: Importing users over time

      As of 1.69.0, you can now update the password hash using the User API.

      From the documentation, the passwordFieldType is the API field to use. This field:

      Describes what user.password in the request is. The possible values are:

      HASHED - user.password is an already hashed value. When this value is supplied, user.encryptionScheme, user.factor, user.password, and user.salt are required.
      PLAINTEXT - user.password is a plain text/unhashed value. FusionAuth will hash this value according to user.encryptionScheme and user.factor.

      posted in Q&A
      danD
      dan
    • RE: Email MFA Timeout

      You want to modify the Two-Factor Login duration in the Tenant Settings, which applies across to SMS and MFA methods.

      https://fusionauth.io/docs/get-started/core-concepts/tenants#advanced has more details.

      posted in Q&A
      danD
      dan
    • Email MFA Timeout

      Users who's email is lagged by 30 - 60 seconds , the emailed MFA verification code has expired by the time they receive them. I've done a Zoom meeting with the user and verified they are doing everything correctly, but their email is web mail based and must be from cloud provider that has a really slow system. They probably get the email about 60 seconds of they click send verification code and it always fails to verify.

      I can't find anything in settings to change the timeout or searching the documentation. Is there a setting for this somewhere that I could change or could Emailed Verification codes be good for at least 90 seconds?

      ported to forum from https://github.com/FusionAuth/fusionauth-issues/issues/3545

      posted in Q&A mfa email timeout
      danD
      dan