billions-morning-53195
06/23/2022, 9:37 PMbig-carpet-38439
06/24/2022, 4:02 PMbig-carpet-38439
06/24/2022, 4:03 PMbillions-morning-53195
06/24/2022, 4:50 PMWill the Okta groups be populated into Datahub? Or Will the Okta groups that the Okta users are part of would be considered at all for authorization perspective?
Okta is used only as Authentication layer and authorization is completely handled by DatHub groups & DataHub policies?
Do we've to manually add newly created Okta users on DataHub to groups(with our own policies) which we have create separately on DataHub?
big-carpet-38439
06/24/2022, 5:22 PMWill the Okta groups be populated into Datahub? Or Will the Okta groups that the Okta users are part of would be considered at all for authorization perspective?
When a user logs in, their groups will be pulled and created in DataHub. This is called just-in-time provisioning. These groups will be considered for authorization, but the groups must have datahub privileges added to them.
Okta is used only as Authentication layer and authorization is completely handled by DatHub groups & DataHub policies?
Correct!
Do we've to manually add newly created Okta users on DataHub to groups(with our own policies) which we have create separately on DataHub?
No. Your users's group membership will come from Okta!billions-morning-53195
06/24/2022, 5:25 PMbig-carpet-38439
06/24/2022, 5:26 PMbig-carpet-38439
06/24/2022, 5:26 PMbillions-morning-53195
06/24/2022, 5:26 PMbig-carpet-38439
06/24/2022, 5:27 PMbillions-morning-53195
06/24/2022, 5:42 PMIf yes, you may need to make sure Okta is configured to return the groups claim to DataHub!
Cool, looks like I have to check with my SSO team for this. Any config I need to pass to datahub-frontend
pod specifically to get the groups? I am passing groups
as an option in the list for AUTH_OICD_SCOPE
. Would this be enough for getting info about user’s groups?billions-morning-53195
06/27/2022, 6:19 PMdatahub-frontend
pod logs-
18:07:03 [application-akka.actor.default-dispatcher-5480] ERROR auth.sso.oidc.OidcCallbackLogic - Unable to renew the session. The session store may not support this feature
Please let me know when you get a chance. Thanksbitter-motherboard-67717
02/25/2023, 7:48 AM