feat: add session_transfer delegation config support for CTE impersonation#1406
Open
ankita10119 wants to merge 4 commits into
Open
feat: add session_transfer delegation config support for CTE impersonation#1406ankita10119 wants to merge 4 commits into
ankita10119 wants to merge 4 commits into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1406 +/- ##
=======================================
Coverage 80.19% 80.19%
=======================================
Files 153 153
Lines 7119 7119
Branches 1573 1573
=======================================
Hits 5709 5709
Misses 760 760
Partials 650 650 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
harshithRai
approved these changes
Jun 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔧 Changes
Added support for
session_transfer.delegationconfiguration on clients, enabling the Custom Token Exchange Impersonation via Session Transfer feature (Phase 2).New optional properties under
session_transfer.delegation:allow_delegated_access(boolean) — allows clients to accept Session Transfer Tokens that contain an Actor, enabling impersonated SSO sessionsenforce_device_binding(string:"ip"|"asn") — enforces device binding for impersonation sessions; defaults to"ip"when omitted📚 References
🔬 Testing
Unit test added in
test/tools/auth0/handlers/clients.tests.js:should allow valid session_transfer delegation property in client— verifies the delegation config iscorrectly passed through to the Management API on client create.
Manual end-to-end test against a tenant with the Custom Token Exchange Delegation feature flag enabled:
session_transfer.delegation.allow_delegated_access: trueandenforce_device_binding: ipto aregular_webclient configa0deploy import- Management API accepted the properties and returned 200📝 Checklist