Configuration of simple realm administration

This configuration uses the context data item realm. It is possible to choose a different context data item (e.g., company) to achieve the same result.

Configuration of the simple realm feature

Prerequisites

  • The choice, which context data item will hold the simple realm value must have been made.
  • The database schema of IAM 7.4 or later is required if the simple realm attribute is to be used.
  • This feature requires the license tag: RealmAdministration

Proceed as follows:

  1. In the Config Editor, go to:
    Adminapp >> Advanced Settings
  2. In the Simple Realm Administration property, create a Simple Realm Administration plugin.
  3. Edit the Simple Realm Administration plugin as follows:
  4. Edit Simple Realm Administration plugin

    1. In the Admin Realm Context Data Name property field, create a String Context Data Item Name plugin. Give the plugin an easily recognizable name in the Display Name field, for example admin-simple-realm. This name is used to reference the plugin later on.
      • In the String Context Data Item Name plugin dialog, in the Context Data Name property field: Set the name of the administrator's context data item holding the simple realm value. For example, admin_realm.
    2. In the User Realm Context Data Name property field, create a String Context Data Item Name plugin. Give the plugin an easily recognizable name in the Display Name field, for example user-simple-realm. This name is used to reference the plugin later on.
      • In the String Context Data Item Name plugin dialog, in the Context Data Name property field: Set the name of the user's context data item holding the simple realm value. For example, user_realm.
  5. This enables IAM to use the simple realm administration feature.

Configuration of the simple realm attribute

Prerequisites

  • The context data item chosen to hold the simple realm value for users must exist in the database schema for end-users.
  • The context data item chosen to hold the simple realm value for administrators must exist in the database schema for administrators.

Instruction part 1 – Add simple realm attribute to the databases of users and administrators

  1. Go to:
    Adminapp >> Users >> User Data Source >> User Store property.
  2. Open the Database User Store plugin specified in the User Store property field.
  3. In the next dialog, open the Database User Persister plugin specified in the Database User Persister property field.
  4. In the Database User Persister plugin dialog, go to the Context Data section.
  5. Add a String Context Data Item plugin to the Context Data Columns list.
    • In the String Context Data Item plugin dialog, in the Context Data Name property field, reference the previously created String Context Data Item Name plugin for end-users. Here, we called this plugin user-simple-realm.
  6. Now go to:
    Adminapp >> Administrators >> Administrator Management >> Admin User Store property.
  7. Open the Database User Store plugin specified in the Admin User Store property field.
  8. In the next dialog, open the Database User Persister plugin specified in the Database User Persister property field.
  9. In the Database User Persister plugin dialog, go to the Context Data section.
  10. Add a String Context Data Item plugin to the Context Data Columns list.
    • In the String Context Data Item plugin dialog, in the Context Data Name property field, reference the previously created String Context Data Item Name plugin for administrators. Here, we called this plugin admin-simple-realm.
  11. The simple realm attribute is now available for both end-users and simple realm administrator.

Instruction part 2 – Add simple realm attribute to the user pages

  1. Go to:
    Adminapp >> Users
  2. Scroll to the User List/Search page section and go to the Columns In User List list.
  3. Add a String User Profile Item plugin to the list:
  4. Configure the String User Profile Item plugin as follows:

    1. Display Name: Set Simple Realm Admintool Label.
    2. String Resource Key: Set the identifier for the language-specific string tables.
    3. Property Name: Set the end-user's simple realm context data attribute.
    4. Optional: Not set, because the simple realm attribute is mandatory.
    5. Modifiable: Not set, because the simple realm attribute cannot be changed.
    6. Prefill – Create a Realm Value Provider plugin with the value @realm@.
  5. Go to:
    Adminapp >> Users
  6. Scroll to the User Details Page - General section and go to the Rows On User Detail Page list.
  7. Add the previously created String User Profile Item with display name Simple Realm Admintool Label.
  8. The simple realm attribute is now visible in the user list, the user detail page and in the user create dialog. The simple realm attribute will be prefilled with the simple realm value.

Instruction part 3 – Username prefixed with the simple realm value (optional)

  1. These steps are optional and only required if the username should be prefixed with the simple realm value.

  2. Go to:
    Adminapp >> Users
  3. Scroll to the Advanced Settings section and go to the Username Prefill property field.
  4. Create a Realm Value Provider plugin and specify the required prefill pattern in the Value plugin property. Here, we used @realm@.
  5. Return to the Advanced Settings section of the previous plugin dialog and go the Username Validator property field.
  6. Create a Simple Realm Username Validator plugin and specify the required username pattern in the Username Pattern plugin property, e.g., @realm@-[a-z]{4,}.
  7. The username will now be prefilled with the simple realm value and validated.

Add simple realm attribute to the administrator pages

Proceed as follows:

  1. Go to:
    Adminapp >> Administrators >> Administrators Management >> Columns in Admin List
  2. Add a String User Profile Item plugin to the list:
  3. Configure the String User Profile Item plugin as follows:

    1. Display Name: Set Simple Realm Admintool Label ADMIN
    2. Property Name: Set the admin's simple realm context data attribute.
    3. Optional: Set enabled (the simple realm attribute is optional).
    4. Modifiable: Set enabled, to make the simple realm attribute changeable.
  4. Go to:
    Adminapp >> Administrators >> Administrators Management >> Rows on Admin Detail Page
  5. Add the previously created String User Profile Item with display name Simple Realm Admintool Label ADMIN.
  6. The simple realm attribute is now visible in the simple realm administrator's list, administrator detail page and the administrator create dialog.