Administrators Management
enforceRoleCombinations) assignableRoleCombinations) Defines a list of roles (or combination of roles). Only the specified roles (or combination of roles) can be assigned to the administrators.
Role combinations are specified using comma-separate entries (e.g. "useradmin,tokenadmin"). These combinations can only be assigned to or removed from an admin together. At least one role (or combination of roles) must contain the "superadmin" role.
Translations for the roles displayed in the administrators management UI can be defined using the Adminapp translation keys roles.admin.labels.[rolename], where [rolename] is one of the entries. E.g.:
- roles.admin.labels.useradmin = User Admin
- roles.admin.labels.useradmin,tokenadmin = Special Admin
privilegeEscalationProtectedAdminRoles) Defines a list of protected roles. Operations on an administrator with one of these roles can only be performed by another administrator that also at least has one of these roles assigned.
Each entry contains a single role.
superAdminRole) passwordGenerator) passwordHashFunction) NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.
columnsInAdminList) The data for the columns is taken from the context data container of the available administrators. The configuration of the used admin persister must include the context data properties referenced here.
The columns are displayed in addition to the following columns:
- username
- assigned roles
- locked flag
rowsOnAdminDetailPage) The data for is taken from the context data container of the selected administrator. The configuration of the used admin persister must include the context data properties referenced here.
adminUserStore) lockReasons)
type: AdministratorsManagement
id: AdministratorsManagement-xxxxxx
displayName:
comment:
properties:
adminUserStore:
assignableRoleCombinations:
columnsInAdminList:
enforceRoleCombinations: true
lockReasons: [LockReason.InitiatedByAdmin]
passwordGenerator:
passwordHashFunction:
privilegeEscalationProtectedAdminRoles:
rowsOnAdminDetailPage:
superAdminRole: