Group resolution: OIDC groups claim + LDAP memberOf → permission groups #17

Closed
opened 2026-07-25 16:25:36 +00:00 by Cordy · 0 comments
Owner

Feed the §5.4 per-group spaces. OIDC already reads a configurable groups claim; LDAP memberOf/group-search is implemented but not yet exercised end-to-end.

  • Normalize both sources into a single group set on the User.
  • Wire into the authz model (group → /spaces/<group> visibility).
  • Interop test group-driven access against live Keycloak + a directory.

Prereq for per-group spaces.

Feed the §5.4 per-group spaces. OIDC already reads a configurable `groups` claim; LDAP `memberOf`/group-search is implemented but **not yet exercised end-to-end**. - Normalize both sources into a single group set on the `User`. - Wire into the authz model (group → `/spaces/<group>` visibility). - Interop test group-driven access against live Keycloak + a directory. Prereq for per-group spaces.
Cordy closed this issue 2026-07-25 20:15:21 +00:00
Sign in to join this conversation.
No labels
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: Cordy/Cairn#17
No description provided.