Replies: 3 comments 6 replies
-
|
I created a bug for the Still it would be nice if this inheritance would somehow apply for all group related permissions :) |
Beta Was this translation helpful? Give feedback.
-
|
I think this would become extremely complicated if we allowed inheritance. Also, current users may be relying on the current behavior. So inheritance would have to be optional. |
Beta Was this translation helpful? Give feedback.
-
|
I am evaluating the fine-grain-admin-authz feature. My Keycloak version is 26.1.4. Note: I have also mentioned the same comment here |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi everyone,
I am currently trying out some things with the fine grained authorization for groups and found out that it seems it is currently not possible to inherit permissions to child groups. Example:
query-groupsparentparentwith the name childparentviewpermission of theparentgroupYou will then be able to view the parent group but will receive a 403 error when trying to access the child group. Same thing applies for the other permissions (e.g. view-members -> with the
query-usersrole added to the user I will only see users of the parent role, but not of the child role in the users overview). Only workaround would be to explicitly add permissions to every group.In my opinion group permissions should be extended to the children.
You are also able to see all groups in the overview, not only the once you have the view permission for (maybe a filter should be added here?)
Beta Was this translation helpful? Give feedback.
All reactions