diff --git a/.forgejo/workflows/test.yaml b/.forgejo/workflows/verify.yaml similarity index 53% rename from .forgejo/workflows/test.yaml rename to .forgejo/workflows/verify.yaml index eaba13b..9f88d22 100644 --- a/.forgejo/workflows/test.yaml +++ b/.forgejo/workflows/verify.yaml @@ -1,10 +1,12 @@ on: pull_request: push: + branches: + - main jobs: - test: - name: Test + ansible-lint: + name: Verify runs-on: docker steps: - uses: actions/checkout@v7 @@ -12,6 +14,6 @@ jobs: run: | apt update apt install -y maven - - name: Run maven verify test + - name: Run maven verify run: | - mvn -f attribute-endpoints-provider verify test + mvn -f attribute-endpoints-provider --batch-mode --no-transfer-progress verify diff --git a/README.md b/README.md index 3c9986e..9cd3766 100644 --- a/README.md +++ b/README.md @@ -1,39 +1,16 @@ -# Attribute Endpoints Provider - Export User Attributes +# Attribute Endpoints Provider -This is a Keycloak Provider that exports user profile attribute values. -The selection of attributes and authorization is manage through an endpoint configuration. +This is a Keycloak Provider that exports an anonymized list of user profile attribute values. +For this it will provide API endpoints for every configured attribute-group. +The configuration of the provider is possible via an admin page. -## Usage - -The provider adds an object type "Attribute Endpoints" to the Keycloak admin website. -You configure the provider by creating one or more endpoint configurations. - -Each endpoint configuration requires: -- a name that is the reference in the endpoint URL (slug) -- the name of a role that the calling user must have to be allowed to query this endpoint -- the name of an attribute or an attribute group that should be exported -- the name of a role that users must have to be included in the list -- an optional regular expression that must match to have a value included -- whether to default to the user email if the attribute is empty - -> **Note** The attribute (group) and the roles need to exist before you can create the endpoint configuration. - -There are two endpoints returning JSON: -- `export/slug`: collate all attribute values into a single list -- `export/slug/map`: produce a map of lists, with the key being the attribute name - -No other data is included in the response, in particular, there is no information on which attribute value is associated with which user. - -User Attribute values can be single or multi-value; the resulting list will include them as a flattened list. - -> **⚠️ Note** The authorization and the selection of the user attributes are not tied together in any way. -> Every user that has the matching role will have all the attributes included that are specified in the endpoint configuration. -> In other words, if you are exporting an attribute group, all attributes will be included. - -> **⚠️ Note** Keycloak has no concept of authorization for individual user attributes (for example, based on assigned roles). -> Users will be able to see and edit any attribute that has been made available to users, irrespective of whether a user would -> be included in an endpoint configuration export or not. +Every endpoint responds with a list of all attribute values, that: +- are in the attribute group matching `attribute-group` +- match an optional RegEx Pattern `attribute-regex` +- belong to a user with a role matching `match-role` +- are non-empty +Multivalue attributes are flattened in the response. ## Building @@ -43,8 +20,79 @@ Once all dependencies are met, simply call `make` to build the provider, which s There's also `make clean` available for removing the output directory. -To add the provider to your Keycloak install, copy `attribute-endpoints-provider/target/attribute-endpoints-provider-1.0-SNAPSHOT.jar` to the Keycloak Provider directory (`/opt/keycloak/providers/). - ## Testing Setup See [testing/README.md](testing/README.md) for details on the Docker Compose based setup that includes a realm and the ability to attach a debugger to the running Keycloak. + +## Example Setup + +We assume an unconfigured, fresh Keycloak installation running under `http://localhost:8080`. +(This can be achieved by running the provided `compose.yaml` after building the provider as outlined in [Building](#building).) + + 1. Add a new realm + e.g. "TestRealm" + 2. Under `Realm Settings > User profile > Attributes Group`, add a new attribute Group + Example: + - `Name` = `"my-attributes-group"` + - `Display name` = `"Endpoint Attributes"` + - `Display description` = `"Attributes exported by the provider."` + 3. Under `Realm Settings > User profile > Attributes`, add a new attribute + Example: + - `Attribute [Name]` = `"ssh-keys"` + - `Display name ` = `"SSH Keys"` + - `Multivalued` = `On` + - `Attribute group` = `"my-attributes-group"` + - `Who can edit?` = `user, admin` + - `Validators` + You can add validators, which will limit what values the user can enter. These validators are ignored by the provider. + 4. Under `Realm roles`, add two new roles + Example: + 1. `Role name` = `"myattribute-match"` + 2. `Role name` = `"myattribute-export"` + 5. Under `Users`, add a new user + Example: + - `Username` = `"user"` + - `Email` = `"user@example.com"` + - `First name` = `"User"` + - `Last name` = `"User"` + - `SSH Keys` = `"example-value-1", "example-value-2"` + 6. In the Settings of the newly created user, go to `Role mapping > Assing role > Realm roles` and check the role `myattribute-match` + 7. create a second user to use the provider + - `Username` = `"bot-user"` + - `Email` = `"bot@example.com"` + - `First name` = `"Bot"` + - `Last name` = `"Bot"` + - After creating: + - give it the role `myattribute-export` + - set a password in the users settings `Creadentials > Set password`. For Example `"password"` +8. Under `Attribute Endpoints > Create item`, add a new endpoint to the provider + Example: + - `Slug` = `"ssh_keys"` + - `Attribute Group` = `"my-attributes-group"` + - `Match Role` = `"myattribute-match"` + - `Auth Role` = `"myattribute-export"` + - `Attribute RegEx` = `".*"` +9. Aquire an OIDC Access Token: + ```shell + curl --request POST \ + --url http://localhost:8080/realms/TestRealm/protocol/openid-connect/token \ + --header 'content-type: application/x-www-form-urlencoded' \ + --data scope=openid \ + --data username=bot-user \ + --data password=password \ + --data grant_type=password \ + --data client_id=admin-cli + ``` +10. copy the value of the response key `access_token` and use it in a second request: + ```shell + curl --request GET \ + --url http://localhost:8080/realms/TestRealm/attribute-endpoints-provider/export/ssh_keys \ + --header 'authorization: Bearer ey...' \ + --header 'content-type: application/json' + ``` +11. You should get a response like this: + ```json + ["example-value-1","example-value-2"] + ``` + +Although this example uses a simple bot account to authenticate to Keycloak, we recommend using a client with service account, when using this provider programmatically. diff --git a/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AdminUiPage.java b/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AdminUiPage.java index eec6aa1..cfd26b6 100644 --- a/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AdminUiPage.java +++ b/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AdminUiPage.java @@ -1,12 +1,15 @@ package de.ccc.hamburg.keycloak.attribute_endpoints; -import com.google.auto.service.AutoService; +import java.util.List; +import java.util.regex.Pattern; + import org.keycloak.Config; import org.keycloak.component.ComponentModel; import org.keycloak.component.ComponentValidationException; import org.keycloak.models.KeycloakSession; import org.keycloak.models.KeycloakSessionFactory; import org.keycloak.models.RealmModel; +import org.keycloak.models.RoleModel; import org.keycloak.provider.ProviderConfigProperty; import org.keycloak.provider.ProviderConfigurationBuilder; import org.keycloak.representations.userprofile.config.UPConfig; @@ -14,8 +17,7 @@ import org.keycloak.services.ui.extend.UiPageProvider; import org.keycloak.services.ui.extend.UiPageProviderFactory; import org.keycloak.userprofile.UserProfileProvider; -import java.util.List; -import java.util.regex.Pattern; +import com.google.auto.service.AutoService; /** * Implements UiPageProvider to show a config page in the admin @@ -41,7 +43,6 @@ public class AdminUiPage implements UiPageProvider, UiPageProviderFactory - a.getName().equals(configAttributeGroup) - || (a.getGroup() != null && a.getGroup().equals(configAttributeGroup)))) { + } else if (!upconfig.getGroups().stream().anyMatch(g -> g.getName().equals(configAttributeGroup))) { hasError = true; - errorString += " • [Attribute Group] no matching Attribute or Attribute Group\n"; + errorString += " • [Attribute Group] does not exist\n"; } String configAttributeRegex = model.getConfig().getFirst("attribute-regex"); - boolean regexIsBlank = configAttributeRegex == null; + Boolean regexIsBlank = configAttributeRegex == null; if (!regexIsBlank) { try { @@ -114,47 +113,40 @@ public class AdminUiPage implements UiPageProvider, UiPageProviderFactory attribute_list = ctx.users .map(user -> { - Stream attributeStream = ctx.attributeNames.stream(); - - attributeStream = attributeStream.map(attributeName -> ctx.MapUserAttribute(user, attributeName).toList()) + Stream attributeStream = ctx.attributeNames.stream() + .map(attributeName -> user.getAttributeStream(attributeName).toList()) .flatMap(Collection::stream); return attributeStream @@ -68,46 +66,14 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider return Response.ok(attribute_list).build(); } - /** - * Return a map of lists of attribute values. For each attribute in the named attribute - * group, add an entry in the resulting map with the attribute name as the key, and the - * values as a list as the values. - * - * @param attributeGroupName attribute group name - * @return a map of attribute names and their values - */ - @GET - @Path("export/{attributeGroupName}/map") - @Produces(MediaType.APPLICATION_JSON) - public Response exportAttributeValuesMap(@PathParam("attributeGroupName") String attributeGroupName) { - AttributeExportContext ctx = new AttributeExportContext(attributeGroupName); - - List userList = ctx.users.toList(); - - Map> attributeMap = ctx.attributeNames.stream() - .collect(Collectors.toMap( - attributeName -> attributeName, - attributeName -> userList.stream() - .flatMap(user -> ctx.MapUserAttribute(user, attributeName)) - .filter(attribute -> !attribute.isEmpty()) - .filter(ctx.filter::matches) - .toList())); - - return Response.ok(attributeMap).build(); - } - - /** * Resolves and validates the configuration and request state needed to export attribute * values for a given slug, exposing the results as member variables. */ private class AttributeExportContext { - final Pattern validEmail = Pattern.compile("@"); - List attributeNames; UserModel authUser; String configAttributeGroup; - boolean defaultToUserEmail; RegExFilter filter; UPConfig upconfig; Stream users; @@ -121,38 +87,37 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider .toList(); if (componentList.isEmpty()) { - throw new NotFoundException("Attribute Endpoint " + slug + " not found"); + throw new NotFoundException("Endpoint not found."); } if (componentList.size() > 1) { throw new NotFoundException( - "Attribute Endpoint Configuration Error - Multiple configurations exist for " + slug); + "Endpoint Configuration Error - Multiple configurations exist for this endpoint."); } ComponentModel component = componentList.get(0); RoleModel authRole = realm.getRole(component.getConfig().getFirst("auth-role")); if (authRole == null) { - throw new ServerErrorException("Attribute Endpoint " + slug + " Configuration Error - auth-role does not exist.", 500); + throw new ServerErrorException("Endpoint Configuration Error - auth-role does not exist.", 500); } RoleModel matchRole = realm.getRole(component.getConfig().getFirst("match-role")); if (matchRole == null) { - throw new ServerErrorException("Attribute Endpoint " + slug + " Configuration Error - match-role does not exist.", 500); + throw new ServerErrorException("Endpoint Configuration Error - match-role does not exist.", 500); } upconfig = session.getProvider(UserProfileProvider.class).getConfiguration(); configAttributeGroup = component.getConfig().getFirst("attribute-group"); - if (upconfig.getGroups().stream().noneMatch(g -> g.getName().equals(configAttributeGroup)) && - upconfig.getAttributes().stream().noneMatch(a -> a.getName().equals(configAttributeGroup))) { - throw new ServerErrorException("Attribute Endpoint " + slug + " Configuration Error - no attribute or attribute group named " + configAttributeGroup + " found", 500); + if (upconfig.getGroups().stream().noneMatch(g -> g.getName().equals(configAttributeGroup))) { + throw new ServerErrorException("Endpoint Configuration Error - attribute-group does not exist.", 500); } try { filter = new RegExFilter(component.getConfig().getFirst("attribute-regex")); } catch (Exception e) { throw new ServerErrorException( - "Attribute Endpoint " + slug + " Configuration Error - attribute-regex is not a valid regex pattern.", 500); + "Endpoint Configuration Error - attribute-regex is not a valid regex pattern.", 500); } authUser = AttributeEndpointsResourceProvider.getAuth(session).getUser(); @@ -164,34 +129,13 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider // select all attributes that match configAttributeGroup, or that are in a group that matches configAttributeGroup attributeNames = upconfig.getAttributes() .stream() - .filter(a -> - a.getName().equals(configAttributeGroup) - || (a.getGroup() != null && a.getGroup().equals(configAttributeGroup))) + .filter(a -> a.getGroup() != null && a.getGroup().equals(configAttributeGroup)) .map(UPAttribute::getName) .toList(); UserProvider userProvider = session.users(); users = userProvider.searchForUserStream(realm, Map.of()) .filter(user -> user.hasRole(matchRole)); - defaultToUserEmail = Boolean.parseBoolean(component.getConfig().getFirstOrDefault("default-to-user-email", "false")); - } - - /** - * If defaultToUserEmail is set, default to user email if no attribute exists, and remove any value that is not - * a valid email address. - * - * @param user the user whose attributes are being exported - * @param attributeName the attribute to export - * @return a stream of attribute values - */ - Stream MapUserAttribute(UserModel user, String attributeName) { - if (defaultToUserEmail) { - // need to load everything otherwise we can't check for non-existent attribute - Map> attrs = user.getAttributes(); - return attrs.getOrDefault(attributeName, - List.of(user.getEmail())).stream().filter(v -> !validEmail.matcher(v).matches()); - } - return user.getAttributeStream(attributeName); } } diff --git a/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java b/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java index 559f208..7458a1f 100644 --- a/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java +++ b/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java @@ -24,9 +24,7 @@ import java.util.Map; import java.util.function.Supplier; import java.util.stream.Stream; -import static org.junit.Assert.assertEquals; -import static org.junit.Assert.assertThrows; -import static org.junit.Assert.assertTrue; +import static org.junit.Assert.*; import static org.mockito.ArgumentMatchers.*; import static org.mockito.Mockito.mock; import static org.mockito.Mockito.when; @@ -68,36 +66,34 @@ public class AttributeEndpointsResourceProviderTest { List components = List.of( attributeEndpointComponent("dooris-ssh-keys", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys", - false), + "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"), attributeEndpointComponent("mailing-list-addresses-chaos", - "export-mailing-list-addresses", "mailing-list-chaos-member", MAILING_LIST_CHAOS, - true), + "export-mailing-list-addresses", "mailing-list-chaos-member", MAILING_LIST_CHAOS), attributeEndpointComponent("mailing-list-addresses-intern", - "export-mailing-list-addresses", "mailing-list-intern-member", MAILING_LIST_INTERN, - true)); + "export-mailing-list-addresses", "mailing-list-intern-member", MAILING_LIST_INTERN)); when(realm.getComponentsStream()).thenAnswer(inv -> components.stream()); UserProfileProvider userProfileProvider = mock(UserProfileProvider.class); when(session.getProvider(UserProfileProvider.class)).thenReturn(userProfileProvider); when(userProfileProvider.getConfiguration()).thenReturn(testUserProfileConfig()); - hacker = user("hacker", "hacker@example.net", Map.of( - SSH_KEY_1, List.of("hacker-ssh-key-1"), - SSH_KEY_2, List.of("hacker-ssh-key-2"), - MAILING_LIST_INTERN, List.of("hacker+intern@example.net")), + hacker = user("hacker", Map.of( + SSH_KEY_1, "hacker-ssh-key-1", + SSH_KEY_2, "hacker-ssh-key-2", + MAILING_LIST_CHAOS, "hacker+chaos@example.net", + MAILING_LIST_INTERN, "hacker+intern@example.net"), List.of("dooris-authorized", "mailing-list-chaos-member", "mailing-list-intern-member")); - tester = user("tester", "tester@example.com", Map.of( - SSH_KEY_1, List.of("tester-ssh-key-1"), - SSH_KEY_2, List.of("tester-ssh-key-2"), - MAILING_LIST_CHAOS, List.of("tester+chaos@example.com"), - MAILING_LIST_INTERN, List.of("tester+intern@example.com")), + tester = user("tester", Map.of( + SSH_KEY_1, "tester-ssh-key-1", + SSH_KEY_2, "tester-ssh-key-2", + MAILING_LIST_CHAOS, "tester+chaos@example.com", + MAILING_LIST_INTERN, "tester+intern@example.com"), List.of("mailing-list-chaos-member")); - noone = user("noone", "noone@example.org", Map.of( - SSH_KEY_1, List.of("noone-ssh-key-1"), - SSH_KEY_2, List.of("noone-ssh-key-2"), - MAILING_LIST_CHAOS, List.of("noone+chaos@example.org"), - MAILING_LIST_INTERN, List.of("noone+intern@example.org", "-")), + noone = user("noone", Map.of( + SSH_KEY_1, "noone-ssh-key-1", + SSH_KEY_2, "noone-ssh-key-2", + MAILING_LIST_CHAOS, "noone+chaos@example.org", + MAILING_LIST_INTERN, "noone+intern@example.org"), Collections.emptyList()); UserProvider userProvider = mock(UserProvider.class); @@ -116,6 +112,7 @@ public class AttributeEndpointsResourceProviderTest { } } + /* NOTYET @Test public void exportAttributeValuesMap_doorisSlug_returnsSshKeysPerAttribute() { try (Response response = callAuthenticatedAs("export-dooris-ssh-keys", @@ -128,7 +125,9 @@ public class AttributeEndpointsResourceProviderTest { response.getEntity()); } } + */ + /* NOTYET @Test public void exportAttributeValues_mailingListChaosSlug_returnsAddressesOfAllMatchingUsers() { try (Response response = callAuthenticatedAs("export-mailing-list-addresses", @@ -136,10 +135,12 @@ public class AttributeEndpointsResourceProviderTest { .exportAttributeValues("mailing-list-addresses-chaos"))) { assertEquals(200, response.getStatus()); - assertEquals(List.of("hacker@example.net", "tester+chaos@example.com"), response.getEntity()); + assertEquals(List.of("hacker+chaos@example.net", "tester+chaos@example.com"), response.getEntity()); } } + */ + /* NOTYET @Test public void exportAttributeValues_mailingListInternSlug_returnsAddressOfSingleMatchingUser() { try (Response response = callAuthenticatedAs("export-mailing-list-addresses", @@ -150,7 +151,9 @@ public class AttributeEndpointsResourceProviderTest { assertEquals(List.of("hacker+intern@example.net"), response.getEntity()); } } + */ + /* NOTYET @Test public void exportAttributeValuesMap_mailingListChaosSlug_returnsAddressesPerAttribute() { try (Response response = callAuthenticatedAs("export-mailing-list-addresses", @@ -159,10 +162,11 @@ public class AttributeEndpointsResourceProviderTest { assertEquals(200, response.getStatus()); assertEquals(Map.of(MAILING_LIST_CHAOS, - List.of("hacker@example.net", "tester+chaos@example.com")), + List.of("hacker+chaos@example.net", "tester+chaos@example.com")), response.getEntity()); } } + */ @Test public void exportAttributeValues_unknownSlug_throwsNotFound() { @@ -178,11 +182,9 @@ public class AttributeEndpointsResourceProviderTest { public void exportAttributeValues_duplicateSlugConfiguration_throwsNotFound() { List duplicateComponents = List.of( attributeEndpointComponent("duplicate-slug", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys", - false), + "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"), attributeEndpointComponent("duplicate-slug", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys", - false)); + "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys")); when(realm.getComponentsStream()).thenAnswer(inv -> duplicateComponents.stream()); NotFoundException exception = assertThrows(NotFoundException.class, @@ -197,8 +199,7 @@ public class AttributeEndpointsResourceProviderTest { public void exportAttributeValues_missingAuthRole_throwsServerError() { List components = List.of( attributeEndpointComponent("bad-auth-role", - "nonexistent-role", "dooris-authorized", "dooris-ssh-keys", - false)); + "nonexistent-role", "dooris-authorized", "dooris-ssh-keys")); when(realm.getComponentsStream()).thenAnswer(inv -> components.stream()); ServerErrorException exception = assertThrows(ServerErrorException.class, @@ -213,8 +214,7 @@ public class AttributeEndpointsResourceProviderTest { public void exportAttributeValues_missingMatchRole_throwsServerError() { List components = List.of( attributeEndpointComponent("bad-match-role", - "export-dooris-ssh-keys", "nonexistent-role", "dooris-ssh-keys", - false)); + "export-dooris-ssh-keys", "nonexistent-role", "dooris-ssh-keys")); when(realm.getComponentsStream()).thenAnswer(inv -> components.stream()); ServerErrorException exception = assertThrows(ServerErrorException.class, @@ -228,8 +228,7 @@ public class AttributeEndpointsResourceProviderTest { @Test public void exportAttributeValues_invalidAttributeRegex_throwsServerError() { ComponentModel component = attributeEndpointComponent("bad-regex", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys", - false); + "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"); component.put("attribute-regex", "["); when(realm.getComponentsStream()).thenAnswer(inv -> Stream.of(component)); @@ -268,14 +267,13 @@ public class AttributeEndpointsResourceProviderTest { } private static ComponentModel attributeEndpointComponent(String slug, String authRole, String matchRole, - String attributeGroup, boolean defaultToUserEmail) { + String attributeGroup) { ComponentModel component = new ComponentModel(); component.setProviderId(AdminUiPage.PROVIDER_ID); component.put("slug", slug); component.put("auth-role", authRole); component.put("match-role", matchRole); component.put("attribute-group", attributeGroup); - component.put("default-to-user-email", Boolean.toString(defaultToUserEmail)); return component; } @@ -299,15 +297,13 @@ public class AttributeEndpointsResourceProviderTest { return attribute; } - private UserModel user(String username, String email, Map> attributes, List roleNames) { + private UserModel user(String username, Map attributes, List roleNames) { UserModel user = mock(UserModel.class); when(user.getUsername()).thenReturn(username); - when(user.getEmail()).thenReturn(email.isBlank() ? null : email); - when(user.getAttributes()).thenReturn(attributes); when(user.getAttributeStream(anyString())).thenAnswer(inv -> Stream.empty()); attributes.forEach((name, value) -> - when(user.getAttributeStream(eq(name))).thenAnswer(inv -> value.stream())); + when(user.getAttributeStream(eq(name))).thenAnswer(inv -> Stream.of(value))); when(user.hasRole(any(RoleModel.class))).thenReturn(false); roleNames.forEach(name -> when(user.hasRole(roles.get(name))).thenReturn(true)); diff --git a/testing/import/testing.json b/testing/import/testing.json index c4acac3..dfa0fa7 100644 --- a/testing/import/testing.json +++ b/testing/import/testing.json @@ -447,7 +447,8 @@ "attributes" : { "ssh-key-1" : [ "hacker-ssh-key-1" ], "mailing-list-address-intern" : [ "hacker+intern@example.net" ], - "ssh-key-2" : [ "hacker-ssh-key-2" ] + "ssh-key-2" : [ "hacker-ssh-key-2" ], + "mailing-list-address-chaos" : [ "hacker+chaos@example.net" ] }, "enabled" : true, "createdTimestamp" : 1784376038850, @@ -1477,7 +1478,7 @@ "subType" : "authenticated", "subComponents" : { }, "config" : { - "allowed-protocol-mapper-types" : [ "saml-user-attribute-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-usermodel-property-mapper", "saml-role-list-mapper", "oidc-usermodel-attribute-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "oidc-address-mapper" ] + "allowed-protocol-mapper-types" : [ "saml-user-property-mapper", "oidc-usermodel-property-mapper", "saml-role-list-mapper", "oidc-full-name-mapper", "saml-user-attribute-mapper", "oidc-address-mapper", "oidc-usermodel-attribute-mapper", "oidc-sha256-pairwise-sub-mapper" ] } }, { "id" : "a49de9bf-462b-4c61-bb52-0373732f4b1b", @@ -1537,7 +1538,7 @@ "subType" : "anonymous", "subComponents" : { }, "config" : { - "allowed-protocol-mapper-types" : [ "saml-user-attribute-mapper", "oidc-usermodel-attribute-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-full-name-mapper", "saml-role-list-mapper", "oidc-usermodel-property-mapper", "oidc-address-mapper", "saml-user-property-mapper" ] + "allowed-protocol-mapper-types" : [ "saml-role-list-mapper", "saml-user-attribute-mapper", "oidc-usermodel-attribute-mapper", "oidc-usermodel-property-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "oidc-address-mapper", "oidc-sha256-pairwise-sub-mapper" ] } }, { "id" : "dd4024e9-f080-4319-aeb7-7f9906c345c5", @@ -1604,9 +1605,8 @@ "subComponents" : { }, "config" : { "match-role" : [ "mailing-list-intern-member" ], - "default-to-user-email" : [ "true" ], + "attribute-group" : [ "mailing-list-addresses" ], "auth-role" : [ "export-mailing-list-addresses" ], - "attribute-group" : [ "mailing-list-address-intern" ], "slug" : [ "mailing-list-addresses-intern" ] } }, { @@ -1625,9 +1625,8 @@ "subComponents" : { }, "config" : { "match-role" : [ "mailing-list-chaos-member" ], - "default-to-user-email" : [ "true" ], - "attribute-group" : [ "mailing-list-address-chaos" ], "auth-role" : [ "export-mailing-list-addresses" ], + "attribute-group" : [ "mailing-list-addresses" ], "slug" : [ "mailing-list-addresses-chaos" ] } } ]