Project

General

Profile

Actions

Task #1173

open

Add permission to disable SSO

Added by Alena Peterová over 6 years ago.

Status:
New
Priority:
Normal
Assignee:
Radek Tomiška
Category:
Authentication / Authorization
Target version:
-
Start date:
07/16/2018
Due date:
% Done:

0%

Estimated time:
Owner:

Description

This follow the implementation of SSO as consulted in #1095#note-3.
Add a new permission "App configuration" - "SSO disabled". Admins, who have some role with this permission, won't be authenticated by SsoIdmAuthenticationFilter.

Check the method IdmAuthorizationPolicyService#getGrantedAuthorities when processing APP group permission (APP != APP_ADMIN).
Create IdmAuthorizationPolicyService#getAssignedAuthorities so it returns all effective authorities without trimming.

No data to display

Actions

Also available in: Atom PDF