Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-1635

Ensure security realms assign users to groups and not roles by default.

    XMLWordPrintable

Details

    Description

      Currently we only use group/role assignment within the ApplicationRealm where there is an assumption of a 1:1 mapping between a group and a role.

      Instead by default the <authorization /> section of a <security-realm /> should be used to load group membership information.

      Within access control the group to role mapping will happen at a later point as it needs to take into account the address or an operation.

      For situations where a 1:1 mapping can be assumed we will add a configuration option on the <authorization /> element - 'map-groups-to-roles' default will be false.

      For backwards compatibility the ApplicationRealm we ship will have 'map-groups-to-roles' set to true. Where an older schema is read we will assume this attribute was set to true for consistency.

      Attachments

        Activity

          People

            darran.lofthouse@redhat.com Darran Lofthouse
            darran.lofthouse@redhat.com Darran Lofthouse
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: