Project

General

Profile

Actions

Feature #20640

open

API for admin to query materialized permissions

Added by Peter Amstutz 6 months ago. Updated 5 months ago.

Status:
New
Priority:
Normal
Assigned To:
-
Category:
API
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Story points:
-

Description

Requested by user:

They would like to synchronize permissions set in Arvados to another system. This system does not support OpenID, users will log in with LDAP and they can do a mapping between username and arvados uuid. However it is not convenient to generate and use Arvados tokens or do permission lookups on the fly.

Proposed solution is to have an admin API where the client can send a list of users and/or projects and get back the permissions associated with each user and/or project. This would make it possible to write a periodic synchronization task that gets the current permissions from Arvados for the set of users/projects of interest and applies them to the 3rd party system.

Actions #2

Updated by Peter Amstutz 6 months ago

  • Description updated (diff)
Actions

Also available in: Atom PDF