Delegation-based Access Control
Description
Defines Adminapp access control based on realms and delegations.
May be used by
Properties
REST Access Controller (
restServiceAccessController) Description
The Access Controller plugin ensures that the logged-in administrator has permission to access the requested REST resources. The REST access controller can only allow additional access to REST resources, but not restrict it more than defined by the role based access rules below.
Attributes
Plugin-Link
Optional
Assignable plugins
Token Management (
manageTokens) Description
Roles that give the permission to manage (import) tokens. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,useradmin, useradmin, helpdesk
View Technical Clients (
viewTechnicalClients) Description
Roles that give the permission to view technical clients (list with details). At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,techadmin, techadmin, helpdesk
Create And Edit Technical Clients / API Keys / Plans (
createEditTechnicalClient) Description
Roles that give the permission to create and edit technical clients, its API keys and plans. Also allows to delete API keys and plans. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,techadmin, techadmin, helpdesk
Delete Technical Clients (
deleteTechnicalClient) Description
Roles that give the permission to delete technical clients. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,techadmin, techadmin, helpdesk
Lock Technical Clients / API Keys (
lockTechnicalClient) Description
Roles that give the permission to lock technical clients and API keys. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,techadmin, techadmin, helpdesk
Unlock Technical Clients / API Keys (
unlockTechnicalClient) Description
Roles that give the permission to unlock technical clients and API keys. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,techadmin, techadmin, helpdesk
List Maintenance Messages (
listMaintenanceMessages) Description
Roles that give the permission to list maintenance messages. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,systemadmin, systemadmin, helpdesk
Edit Maintenance Messages (
editMaintenanceMessage) Description
Roles that give the permission to edit maintenance messages. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,systemadmin, systemadmin, helpdesk
Delete Maintenance Messages (
deleteMaintenanceMessage) Description
Roles that give the permission to delete maintenance messages. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,systemadmin, systemadmin, helpdesk
Edit Configuration (
editConfig) Description
Roles that give the permission to edit configurations. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,configadmin, configadmin, helpdesk
Apply Configuration (
applyConfig) Description
Roles that give the permission to apply configurations. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
CAUTION: Because administrator access control is also part of the configuration, an administrator with this privilege can possibly gain all possible administrator rights.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,configadmin, configadmin, helpdesk
View Log Files (
viewLog) Description
Roles that give the permission to view log files. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,systemadmin, systemadmin, helpdesk
View License (
viewLicense) Description
Roles that give the permission to view and edit the license. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,systemadmin, systemadmin, helpdesk
Access Service Container Management (
accessServiceContainer) Description
Roles that give the permission to access the service container. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,systemadmin, systemadmin, helpdesk
Manage Realm Roles (
manageRealmRoles) Description
Roles that give the permission to create and delete realm roles to be used in delegations. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,realmadmin, realmadmin
View Delegations (
viewDelegations) Description
Roles that give the permission to view the list of delegations. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,realmadmin, realmadmin
Create Delegation (
createDelegation) Description
Roles that give the permission to create a new delegation. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,realmadmin, realmadmin
Edit Delegation (
editDelegation) Description
Roles that give the permission to edit or delete an existing delegation. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,realmadmin, realmadmin
Create Realm (
createRealm) Description
Roles that give the permission to create a new realm during the creation of a new delegation. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
String
Optional
Suggested values
NO RESTRICTION, superadmin, superadmin,realmadmin, realmadmin
Superadmin Role (
superadminRole) Description
The superadmin role which allows creating any roles or realms. Needed for bootstrapping and self-lockout situation.
Attributes
String
Optional
Suggested values
superadmin
Delegations Repository (
delegationsRepository) Description
Repository for delegations and admin roles.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)
type: DelegationBasedAccessControl
id: DelegationBasedAccessControl-xxxxxx
displayName:
comment:
properties:
accessServiceContainer:
applyConfig:
createDelegation:
createEditTechnicalClient:
createRealm:
delegationsRepository:
deleteMaintenanceMessage:
deleteTechnicalClient:
editConfig:
editDelegation:
editMaintenanceMessage:
listMaintenanceMessages:
lockTechnicalClient:
manageRealmRoles:
manageTokens:
restServiceAccessController:
superadminRole:
unlockTechnicalClient:
viewDelegations:
viewLicense:
viewLog:
viewTechnicalClients: