]
Martin Choma commented on WFCORE-3666:
--------------------------------------
[~mmazanek] did you start work on WFCore part already? Is there anything I can look into?
Provide Elytron alternative to RoleMappingLoginModule
-----------------------------------------------------
Key: WFCORE-3666
URL:
https://issues.jboss.org/browse/WFCORE-3666
Project: WildFly Core
Issue Type: Feature Request
Components: Security
Affects Versions: 4.0.0.Final
Reporter: Martin Choma
Assignee: Martin Mazanek
In picketbox there is RoleMappingLoginModule [1], which takes role as returned from
authorization process and maps to different role. I thought something similar should be
configurable with some of Elytron role-mappers. But looking into model/code, it is not
obvious to me which of them can be used. I know custom role mapper can be still used, but
I wonder if we really do not provide this common funcionality out of the box with
Elytron.
Another workaround is to use direct roles from realm (e.g. LDAP ) in target (e.g.
web.xml). But seems users tend to map IDM Roles to applicaiton roles.
[1]
https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_ap...