Tenant users
Off by default. The Settings -> Users section of the application shell lets a tenant's owners manage who may use the tenant: invite a person with one or more roles, change a member's roles, or remove a member. Generated application shells mount the same section.
DIRIGIBLE_TENANT_USERS_ENABLED=true
DIRIGIBLE_TENANT_USERS_CHANGE_QUEUE=global:acme.user-changesHow it works
The application does not decide membership. Under TOKEN_GROUPS a person's roles in a tenant are their identity provider groups (see Multi-tenancy), and an external provisioning system owns those groups.
The section publishes each owner action as a change request on a message queue, for the external system to carry out or refuse. It shows the tenant's users as the external system reports them back through the tenant provisioning API.
Who may use it
- A holder of the tenant's
Ownerrole, aDEVELOPERor anADMINISTRATORmay manage the users. AnOPERATORmay only see them. - It works on the selected tenant. The default tenant has no users to manage.
- The roles on offer are
OwnerandUser.
Configuration
| Variable | Default | Purpose |
|---|---|---|
DIRIGIBLE_TENANT_USERS_ENABLED | false | Shows the section. |
DIRIGIBLE_TENANT_USERS_CHANGE_QUEUE | The queue the change requests are published to. It replaced DIRIGIBLE_TENANT_USERS_REQUEST_QUEUE. |
With the section on, the application refuses to start unless:
- the tenant resolution strategy is
TOKEN_GROUPS; DIRIGIBLE_TENANT_USERS_CHANGE_QUEUEis set, to aglobal:destination;DIRIGIBLE_TENANT_PROVISIONING_API_ENABLED=true.