Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Roles don't get applied (Authentik) #143

Open
DesertCookie opened this issue Feb 19, 2024 · 4 comments
Open

Roles don't get applied (Authentik) #143

DesertCookie opened this issue Feb 19, 2024 · 4 comments

Comments

@DesertCookie
Copy link

DesertCookie commented Feb 19, 2024

I've successfully set up Authentik as SAML provider and connected it to Wordpress. The login and logout works flawlessly, even transferring custom user attributes for first, last, and nick name.

However, I cannot figure out how to get groups working. In Authentik I have a group wordpress that is required to access the service at all. This group then has sub-groups such as wordpress-editor; these group names I have added to the plugin config. Furthermore, I have tried multiple ways of specifying the attribute mappings for roles: http://schemas.xmlsoap.org/claims/Group is what works for Nextcloud, I've tried groups and also ak_groups see here. User always end up only being subscribers. I've tried both with an without Multiple role values in one saml attribute value.

mappings

@Subterrane
Copy link

The original author of this repo is now at https://github.com/SAML-Toolkits. We still need to transfer this repo to his organization.

@DesertCookie
Copy link
Author

It doesn't make sense to open an issue there yet, though, right?

@Subterrane
Copy link

We got it moved, thanks!

@DesertCookie DesertCookie changed the title Can't figure out roles Roles don't get applied (Authentik) Feb 24, 2024
@DesertCookie
Copy link
Author

DesertCookie commented Feb 25, 2024

I've changed to using the SSO URL (IdP-initiated Login) from Authentik instead of the SSO URL (Post) one as the latter had issues with missing SAML payloads.

Groups still do not get applied in WordPress.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants