credativ / plutono

Fork of Grafana keeping the Apache License
Apache License 2.0
7 stars 4 forks source link

Support of the 'role_attribute_strict' option in generic OAuth configuration #56

Closed swaykg closed 12 months ago

swaykg commented 1 year ago

Currently, when no role is applied to a user in generic OAuth configuration, the user is authorized as a Viewer or the role specified by the 'auto_assign_org_role' option.

The 'role_attribute_strict' configuration option has been introduced in Grafana 8.x, that denies user access if no role or an invalid role is returned.

Is there a possibility to add this feature for security purposes?

ntap-nmarco commented 12 months ago

I am sorry. We are currently not planning to backport that configuration option. If this changes, we will reopen this issue. I ask for your understanding here.