CASE STUDY 10 / AUTHENTICATION & SOFTWARE

Extending authentication into the session.

Developing workspace authentication and session controls that added two-factor checks beyond the initial sign-in.

ENVIRONMENT

Managed services provider

MY ROLE

In-house development and workspace integration

STATUS

Delivered

Citrix WorkspaceElectronNode.jsTwo-factor authenticationSession controls

01 / THE CHALLENGE

Understanding the problem.

The workspace experience needed authentication and session controls extending beyond the first login. This work sat alongside the design, administration and troubleshooting of Citrix and Remote Desktop Services environments.

  1. 01Initial sign-in
  2. 02Workspace session controls
  3. 03Additional 2FA checks

02 / MY INVESTIGATION

Following the evidence.

I approached the workspace as both an infrastructure environment and a software experience. Initial sign-in was only one point in the session lifecycle where authentication behaviour mattered.

The work involved an Electron/Node.js wrapper around Citrix Workspace, giving me a way to strengthen authentication and session handling within the in-house application.

03 / IMPLEMENTATION

Putting the work into practice.

  1. 01

    Developed workspace authentication and session controls within the in-house software.

  2. 02

    Implemented additional two-factor authentication checks beyond initial login.

  3. 03

    Maintained the software alongside the Citrix and RDS environments it supported.

04 / OUTCOME & EVIDENCE

What the work delivered.

Implemented additional two-factor authentication checks within the workspace experience beyond initial login.

Software implementation

An Electron/Node.js workspace wrapper and associated authentication/session controls.

Delivered behaviour

Additional two-factor checks beyond the initial sign-in.

05 / ENGINEERING PERSPECTIVE

What I take forward.

Working across software and infrastructure helps expose gaps between a platform's default behaviour and the experience an organisation actually needs.

Organisation names are generalised. These accounts describe my work without publishing client systems, internal logs or proprietary source code.