805ea48a36
- Permission/role group name now comes from the config filename (the map key), dropping the redundant `name` field from each YAML and the object types. - The hierarchical mapping emits an `ak_groups` claim (scope `ak_groups`) instead of `groups`, so it never collides with the direct-groups the default profile mapping already emits under `groups` (Authentik overrides same-key claims in an unpredictable order). Apps request the `ak_groups` scope and read that claim.
4 lines
171 B
YAML
4 lines
171 B
YAML
# Permission group akP-rancher-user (name = filename). Grants user
|
|
# access to rancher: bound to the rancher application and mapped to its user role.
|
|
application: rancher
|