SAML2 Authorization configuration #413
Unanswered
artgoldberg
asked this question in
Q&A
Replies: 1 comment
-
|
Hi @artgoldberg and sorry for the slow response. Hopefully, I'm not misunderstanding, but these are claims used essentially for identifying users (ie, authentication) rather than entitlements which Leaf would map to roles (authorization), right? What entitlements are coming across from Shibboleth? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello Leaf Folks
The Leaf installation documentation suggests this starting point for configuring SAML2 authentication and authorization in the Leaf API appsettings:
I'm currently working on getting SAML2 authentication working. I know that our SAML2 IdP (Azure AD) will return emailaddress as a claim name, which I think is a SAML2 attribute. This is its configuration:
Therefore, I'm configuring authentication like this:
Short-term, until SAML2 authentication works, how should I configure authorization so that all users who login are super users?
Thanks
Arthur
Beta Was this translation helpful? Give feedback.
All reactions