aws / amazon-managed-grafana-roadmap

Amazon Managed Grafana Roadmap
Other
60 stars 4 forks source link

Support setting the EDITOR role via SAML assertion #23

Closed brodster2 closed 2 years ago

brodster2 commented 2 years ago

As far as I can understand from the documentation, you can specify users to have the editor role when using AWS SSO as the IDP https://docs.aws.amazon.com/grafana/latest/userguide/Grafana-user-roles.html, but when it comes to using SAML, AMG only lets us specify editor or admin roles https://docs.aws.amazon.com/grafana/latest/userguide/authentication-in-AMG-SAML.html#AMG-SAML-Assertion-Mapping. Can we have a field that lets us set viewer role values?

brodster2 commented 2 years ago

Sorry, figured it out. Any user that doesn't have the attributes specified for the admin or editor role values are automatically assigned the viewer role