Skip to content

Detach unmapped OIDC roles during user sync#11702

Open
tiran133 wants to merge 1 commit into
ILIAS-eLearning:release_10from
tiran133:oidc/mantis/30142
Open

Detach unmapped OIDC roles during user sync#11702
tiran133 wants to merge 1 commit into
ILIAS-eLearning:release_10from
tiran133:oidc/mantis/30142

Conversation

@tiran133

Copy link
Copy Markdown

Description

Update OIDC role synchronisation, so existing users lose mapped global
roles when their provider claims no longer match the configured role
mapping.

Keep role matching behaviour for new users unchanged, while writing a
Role detach action for existing users when a mapped claim is missing or
does not contain the configured value.

Fixes

https://mantis.ilias.de/view.php?id=30142
It would be a change of behaviour, it might need to be gated behind a UI setting?

Update OIDC role synchronisation, so existing users lose mapped global
roles when their provider claims no longer match the configured role
mapping.

Keep role matching behaviour for new users unchanged, while writing a
Role detach action for existing users when a mapped claim is missing or
does not contain the configured value.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant