Webitel: Documentation

Permissions (SSO)

1. Description

Here you select roles and their permissions for this SSO profile.

Consists of the following elements:

  1. Create tool (Fig. 1.(1));

  2. Records registry refresh tool (Fig. 1.(2));

  3. Records registry (Fig. 1.(3));

  4. Pagination (Fig. 1.(4)).

Permissions_(SSO).png
Fig. 1. Permissions detail page

When creating a new SSO profile, the following users/roles are added to the records registry, depending on the following:

  1. if there are no entries in the Managed by records tab of the "sso" section — only the User who creates the profile.

  2. if there are entries on the Managed by records tab of the "sso" section: 

    • the user who creates the profile;

    • those Grantees are listed on the Managed by records tab in the "sso" section for whom the Grantor is the creator of the profile. All the Roles of the User who created the new profile and the User himself are considered as the Grantor.

The entered Roles and their rights concerning this profile are used when Managed by records is enabled on the Objects page (switch in the On position) in the "sso" section.

The Permissions tab shows only the Roles and Users that you can view. If you do not have permission to view other Users, you will only see yourself and your Roles on the Permissions tab, if they are configured there.

1.1. Create tool

The add button is used to add a role. Clicking the add button image-2023-7-18_16-57-30.png?version=1&modificationDate=1694805392591&cacheVersion=1&api=v2&width=20 opens a modal window (Fig. 2). Clicking on the Role field opens a dropdown list containing all roles and users.

To quickly find the needed user or role, the Role field can be used as a search field: enter the name of the user or role you're looking for, and the dropdown list will display only users or roles containing the entered name.

Users and roles can be distinguished by icons:

  • image-2023-7-18_17-7-34.png?version=1&modificationDate=1694805392608&cacheVersion=1&api=v2&height=23 - role;

  • image-2023-7-18_17-7-50.png?version=1&modificationDate=1694805392619&cacheVersion=1&api=v2&height=18 - user.

Clicking on a specific role or user selects it. Clicking the Add button adds the selected role to the records registry. Clicking the Close button closes the modal window without adding an entry. Clicking the close button ( image-2023-7-18_17-9-18.png?version=1&modificationDate=1694805392632&cacheVersion=1&api=v2&height=18 ) closes the modal window without adding an entry.

New grantee.png
Fig. 2. New grantee modal window

An added role or user has the following parameters by default:

  • Read – Allow;

  • Edit – Forbidden;

  • Delete – Forbidden.

These parameters can be changed by selecting the required value in the column's dropdown list.

The user who created the new SSO profile has Allow with delegation access for all actions.

1.2. Records registry refresh tool

Updating the records registry table is performed by clicking the refresh button.

1.3. Records registry

Consists of the following columns:

  • Name — role name;

  • Read — dropdown list with read permissions;

  • Edit — dropdown list with edit permissions;

  • Delete — dropdown list with delete permissions.

The delete %D0%A1%D0%BD%D0%B8%D0%BC%D0%BE%D0%BA%20%D1%8D%D0%BA%D1%80%D0%B0%D0%BD%D0%B0%202024-06-18%20133236.png?version=1&modificationDate=1720439501916&cacheVersion=1&api=v2 button removes the role or user from the list of those with access to the created list.

Access options:

  • Allow — the action is allowed;

  • Allow with delegation — allowed with delegation (the user has the permission themselves and can grant it to others);

  • Forbidden — the action is forbidden.

1.4. Pagination

It consists of the Rows per page field, which indicates the number of entries (it is possible to set from 1 to 1000) per page, and forward and backward buttons for switching pages.

2. Opportunities

2.1. Adding a role or user to the list of those with access to the SSO profile

Goal

Add a role that will have access to the SSO profile

Preconditions

  1. Access to the Admin application;

  2. Access to the SSO section in the Admin application;

  3. Permission to create or edit in the SSO section;

  4. At least one SSO profile exists, or a new one is created;

  5. The role or user to be added exists.

Steps


  1. Click the add button. The New grantee modal window opens.

  2. Click on the Role field. A drop-down list of existing Roles opens.

  3. Select the required Role or User.

  4. Click on the Add button.

Result

The modal window closes. The selected role is added to the registry.

2.2. Removing a role or user from the list of those with access to the SSO profile

Goal

Remove a role from the list of those with access to the SSO profile

Preconditions

  1. Access to the Admin application;

  2. Access to the SSO section in the Admin application;

  3. Permission to create or edit in the SSO section;

  4. At least one SSO profile exists, or a new one is created;

  5. At least one entry exists in the registry.

Steps


  1. Find the Role or User entry you want to remove.

  2. Click on the field in the Read column. A drop-down list will open.

  3. Select Forbidden from the drop-down list by clicking on it.

Result

The Role or User has been removed from the registry.

2.3. Changing permission for actions on the SSO profile

Goal

Change permission for actions

Preconditions

  1. Access to the Admin application;

  2. Access to the SSO section in the Admin application;

  3. Permission to create or edit in the SSO section;

  4. At least one SSO profile exists, or a new one is created;

  5. At least one entry exists in the records registry.

Steps


  1. Find the Role or User whose permission you want to change.

  2. Click the field in the desired column. A drop-down list will open.

  3. Select the required value from the drop-down list and click on it.

Result

The permission for the action is changed in the column.