Skip to content

Role/Group mapping of a user at the RP side for access controls or contextual policies #99

@amonika230995

Description

@amonika230995

There is also a very common requirement in IAM space around Group/role mapping of the user. i.e., the IDP mentions which role/Group the user belongs to and RP maps this at it's end to provide access and set policies.

Ideally I understand that SCIM is used to generally to provision users and we have mentioned JIT is out of scope for IPSIE. But group mapping at the time of user login is real time and I feel it should be part of this spec.

Probably we should make it a standard in OIDC SL1.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions