Skip to content

Conversation

@tz3
Copy link
Member

@tz3 tz3 commented Dec 22, 2025

When federated users' group membership changes in the IdP and they reauthenticate, their role assignments should reflect the change immediately, respecting the IdP's TTL configuration rather than waiting for the role assignment cache to expire.

This change ensures that federated authentication triggers appropriate cache invalidation for role assignments when group membership has changed.

Closes-Bug: #2119031
Change-Id: I79505f3d9e7d9ba46ed6ff40ee0071bdf92b95a0

(cherry picked from commit ad87d82)

When federated users' group membership changes in the IdP and they
reauthenticate, their role assignments should reflect the change
immediately, respecting the IdP's TTL configuration rather than
waiting for the role assignment cache to expire.

This change ensures that federated authentication triggers
appropriate cache invalidation for role assignments when group
membership has changed.

Closes-Bug: #2119031
Change-Id: I79505f3d9e7d9ba46ed6ff40ee0071bdf92b95a0
Signed-off-by: Moutaz Chaara <moutaz.chaara@sap.com>
(cherry picked from commit ad87d82)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants