SoD: Mutual incompatibility of roles in CzechIdM
Old generation of CzechIdM had a feature of Role's incompatibility (https://blog.bcvsolutions.eu/neslucitelnost-roli/). The incompatibility means that you can define restrictions on roles A nad B that will forbid any user or process to assign those to roles together to the same user.
In new generation of CezchIdM we woud like to have a similar feature. However, due to our experiences from CzechIdM deployments on projects we want the incompatibility to be "soft". It means that CzechIdM will allow the user to have incompatible roles assigned to the identity, but an administrator/security manager will be notified about this incident. Security will also have tools to generate reports with users and their incompatible roles.
It would be nice if CzechIdM was able to show a warning sign to the user in role request form and in role request task if the requested role is incompatible with other assigned/requested roles of the identity.
Before the implementation itself begins a better feature specification should be made.
#5 Updated by Radek Tomiška 3 months ago
- Status changed from In Progress to Needs feedback
- Assignee changed from Radek Tomiška to Vít Švanda
- % Done changed from 0 to 90
Feature is implemented:
- incompatible roles can be defined. When role request is enabled, then definition of incompatible role has to be approved (role lifecycle).
- incompatible roles warning is shown on role request, identity roles and business roles
- report of currently assigned incompatible roles to identities is created (in core)
Could you please do a review and update ERD diagram (I'll have to upgrade my PC already :))?