Skip to content

Enable LS Login access for all ELIXIR users. (LS Login: Service #4212) #48

Description

@vschnei

Summary

LS Login: Service #4212: ELIXIR On-Cloud TES-registry

Broaden access to the ELIXIR-on-Cloud service so that any authenticated
ELIXIR user (anyone with an ELIXIR / LS-Login profile)
can sign in and use
the service, while retaining a dedicated manager group that can administer
the LS Login service configuration itself.

Background / current state

The service is registered as a Relying Party (RP) on Life Science Login
(LS AAI). Access is currently restricted to a small management group of
three ELIXIR users
via group membership. As a result, every other ELIXIR
user is blocked at the LS Login authorization step even though they have a
valid ELIXIR profile.

Verification

  • A non-manager ELIXIR user (with a valid LS-Login profile) can complete
    the login flow and reach the service dashboard.
  • A user without an ELIXIR profile is still denied.
  • A manager can open the RP in SPREG and edit its configuration
    (redirect URIs, group assignments) without escalation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions