| `auth-ext.sync.externalId` | `oauth` | This will serve as the external ID for users and as the prefix for the external ID of groups created by this extension. |
| `auth-ext.externalId`| `oauth` | This will serve as the external ID for users and as the prefix for the external ID of groups created by this extension. |
| `auth-ext.tenant` | | A preselected tenant for all operations in this extension. Only required if there are multiple tenants. |
| `auth-ext.sync.user.createMissing` | `true` | If the user is authenticated, the user may be created in APS. |
| `auth-ext.sync.user.requireGroup` | | This is only applicable when `createMissing` is `true`. If this is unset or the OAuth Authorization Server gives the user the specified group/role, then the user record will be created in APS. |
this.logger.trace("User already belongs to APS group mapped to by OIDC group: {}: {} => {}",user.getExternalId(),oidcGroup,group.getName());
if(this.externalizeMatchingInternalGroups){
this.logger.warn("Classifying internal APS group as external: {} => {}",group.getName(),this.externalIdmSource);
// register the group as external
@@ -191,8 +194,6 @@ public class GroupSyncService {
// internal role already existed and the user is already a member
}
if(oidcGroups.remove(oidcGroup)){
this.logger.trace("User already belongs to APS group mapped to by OIDC group: {}: {} => {}",user.getExternalId(),oidcGroup,group.getName());
continue;
}elseif(!this.syncInternalGroups){
this.logger.trace("Internal APS group membership sync disabled; not considering removal of user from APS group: {} => {}",user.getExternalId(),group.getName());