11 ms·
Thank you for this, it’s sorely needed. One thing I didn’t see mention of is group membership. Is this / will this be part of the core offering? Being able to
by dqh 2y ago
Thank you for this, it’s sorely needed.
One thing I didn’t see mention of is group membership. Is this / will this be part of the core offering? Being able to map IDP group membership to permissions within your SaaS is powerful, and in my experience highly desired by clients.
- ucarion 2y agoYeah, we have this -- if you check out the docs for the endpoint where you accept a SAML login[1], there's an `attributes` (map<string, string>) that SSOReady returns to you. That contains the contents of the relevant SAML assertion's AttributeStatement. So if you're familiar with Okta's parlance, both "Attribute Statements" and "Group Attribute Statements" are returned to you in `attributes`. [1]: https://ssoready.com/docs/api-reference/saml/redeem-saml-access-code https://ssoready.com/docs/api-reference/saml/redeem-saml-acc...
- dqh 2y agoMagnificent, thank you!