public inbox for [email protected]
help / color / mirror / Atom feedFrom: Yogesh Mahajan <[email protected]>
To: Viktor Madarasz <[email protected]>
Cc: [email protected] <[email protected]>
Subject: Re: Pgadmin4 Webserver Authentication + Azure SAML SSO , anyone ever managed to configure it?
Date: Tue, 1 Apr 2025 10:00:02 +0530
Message-ID: <CAMa=N=N3-Xf0yQs_KES5Gcx6cwX-XWOS+-06s6XACf-F7SiT-w@mail.gmail.com> (raw)
In-Reply-To: <[email protected]>
References: <[email protected]>
<[email protected]>
Hi,
pgadmin4 only uses Azure AD for authentication. However users logged in
with Azure SSO(or any OAuth2) are the normal users who have all the access
other than adding new users.
Not sure what exactly you mean 'Read only profiles'? What are the
limitations you have seen in pgadmin?
Thanks,
Yogesh Mahajan
EnterpriseDB
On Mon, Mar 31, 2025 at 6:26 PM Viktor Madarasz <[email protected]>
wrote:
> Hi
>
> Pgadmin4 Webserver Authentication + Azure SAML SSO , anyone ever managed
> to configure it?
>
> Trying to switch IdP Provider from Onelogin ( working right now with
> Pgadmin4 + Webserver Authentication + Onelogin as IdP provider to Azure
> SAML SSO.
>
> It looks like the mapped attributes might be the one causing the issue
> coming from Azure side.
>
> The username in a form of [email protected] gets parsed
> correctly but the actual group memberships not being passed along and
> therefore users being logged in with read only profiles and it does not
> respect their group memberships.
>
> Regards
>
> Viktor
>
>
>
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: [email protected]
Cc: [email protected], [email protected], [email protected]
Subject: Re: Pgadmin4 Webserver Authentication + Azure SAML SSO , anyone ever managed to configure it?
In-Reply-To: <CAMa=N=N3-Xf0yQs_KES5Gcx6cwX-XWOS+-06s6XACf-F7SiT-w@mail.gmail.com>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox