Authorization controller

Availability table

Controller availability

Module

Available

module.scripts

Not supported feature

module.keycloak

Supported feature

authorization controller

Allow to define claims on the access token used by OnSphere to access the front-end.

For example, adding the claim data-access will give the user the same right as if it was member of the group data-access.

To have an effect, the claim must be declared inside module.rights as a group. The field externalLink can be empty.

A TokenRequest is available as tokenRequest for each script managing the authentication.

TokenRequest.tokenId

The id (string) of the token generated.

TokenRequest.userId

The id of the user requesting the token.

TokenRequest.firstname

The firstname (string) of the user. This can be null.

TokenRequest.lastname

The lastname (string) of the user. This can be null.

TokenRequest.username

The username (string) of the user. This can be null.

TokenRequest.email

The email (string) of the user. This can be null.

TokenRequest.phoneNumber

The phoneNumber (string) of the user. This can be null.

authorization.add(value: string)

Add a new right to the existing right list.

Arguments:
  • value – The right to add.

authorization.addOtherClaim(key: string, value: object)

Add a new claim or override an existing one. Be careful as this can break the OIDC protocol.

Arguments:
  • key – The name of the claim to add or replace.

  • value – The content of the claim. This must be valid json.