Re: [Geoserver-devel] "ADMIN" vs "ROLE_ADMINISTRATOR"

2024-05-08 Thread Jody Garnett
Hi David, I created a ticket GEOS-11389 to continue the discussion, but perhaps this should go on the "technical debt" wiki page. It is surprisingly complicated. -- Jody Garnett On May 7, 2024 at 11:11:56 AM, David Blasby via Geoserver-devel <

Re: [Geoserver-devel] "ADMIN" vs "ROLE_ADMINISTRATOR"

2024-05-07 Thread David Blasby via Geoserver-devel
Hi, Here are my notes after the PMC meeting. After talking in the PMC meeting, a full-admin should have two roles; * ROLE_ADMINISTRATOR * ADMIN This is how the standard geoserver "admin" user is configured ("release" data dir). See the PMC meeting notes as well. No action for a while because

Re: [Geoserver-devel] "ADMIN" vs "ROLE_ADMINISTRATOR"

2024-05-06 Thread Jody Garnett
Thinking that this may be by design? Admin gets full access, … including by default the rest api. Role Admin is used to unlock some of the data admin screens in the user interface ( and can be set on a workspace or layer level. ) Admin is required for the more advanced user interface screens lik

[Geoserver-devel] "ADMIN" vs "ROLE_ADMINISTRATOR"

2024-05-06 Thread David Blasby via Geoserver-devel
Hi, I was doing some testing for the JWT Headers SSO module, and noticed a problem when accessing the REST API. I've tracked this down to the roles "ADMIN" vs role "ROLE_ADMINISTRATOR". I believe (could be wrong) that the WEB uses the role "ROLE_ADMINISTRATOR", but the REST API uses the role "AD