Experimenting with admins to have 'impersonation' only on a select 'Client' -- using the following as a template - https://www.keycloak.org/docs/latest/server_admin/#_fine_grain_permissions
Does Keycloak offers ability to restrict realm admins to only have 'impersonation' on a particular 'Client'? So far have not been successful with various permutations from the above linked template.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Keycloak User" group.
To unsubscribe from this group and stop receiving emails from it, send an email to keycloak-use...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-user/f2df7943-5f89-46a9-a468-c2bb89c92ac5n%40googlegroups.com.
Yes -- only for a particular client.Description:Current: Admin has 'impersonation' role under 'realm management: Admin can access all Clients in the Ream as any usersPotential Goals via Fine Grain Permissions (FGP): Admin has 'impersonation' role under 'realm management: Admin can only access particular Client FOO as any usersIs the above doable under FGP?
--On Monday, June 28, 2021 at 2:03:21 PM UTC-7 pigor.c...@gmail.com wrote:Hi,Do you mean restrict impersonation only for tokens issued by a particular client?On Mon, Jun 28, 2021 at 5:44 PM Harry M <har...@gmail.com> wrote:Experimenting with admins to have 'impersonation' only on a select 'Client' -- using the following as a template - https://www.keycloak.org/docs/latest/server_admin/#_fine_grain_permissions
Does Keycloak offers ability to restrict realm admins to only have 'impersonation' on a particular 'Client'? So far have not been successful with various permutations from the above linked template.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Keycloak User" group.
To unsubscribe from this group and stop receiving emails from it, send an email to keycloak-use...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-user/f2df7943-5f89-46a9-a468-c2bb89c92ac5n%40googlegroups.com.
You received this message because you are subscribed to the Google Groups "Keycloak User" group.
To unsubscribe from this group and stop receiving emails from it, send an email to keycloak-use...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-user/e5bcf80b-6220-4ce9-8774-21f9015f7af9n%40googlegroups.com.
Hi Pedro:Thank you for all your guidance -- I've been following your tips for: https://lists.jboss.org/pipermail/keycloak-user/2018-April/013576.htmlIn User:Permission: Under 'scope-name: impersonate'Applied 'Client Policy' for Client FOO
Is above the pathway to restricting 'impersonation' to Client FOO?
How do we assign users to have above permission?
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-user/7466cb2a-75a5-418c-8b0e-9a459366ffeen%40googlegroups.com.