# Dynamic role mapping of OIDC Realm ID value to Realm ID field value in document

**URL:** <https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371>\
**Category:** Elasticsearch\
**Created:** [July 2, 2024, 10:31am UTC](https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371 "2024-07-02T10:31:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [July 2, 2024, 10:31am UTC](https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371/1 "2024-07-02T10:31:33Z")

</div>

Hello,

Looking for some suggestions regarding dynamic role mapping between Realm ID field value returned from OIDC token claim and Realm ID field value in document.

Could not find strong documentation regarding it. Is it possible to implement dynamic role mapping in Elasticsearch for it?  
For example, when someone logs into Kibana and returned token claim metadata contains specific Realm ID, that person should be able to see documents containing only corresponding Realm ID value.

I have reached it by creating static role / role mapping where provided specific Realm ID, but is it possible to make it dynamic?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 4, 2024, 2:44am UTC](https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371/2 "2024-07-04T02:44:09Z")

</div>

_Maybe_, depending on how closely the two values line up.

There's no easy way to have a translation table, so if your OIDC claim is something like "org-12345" but your docs contain "/ORG/ENG/12345" then it's going to tricky.

However, if they're an exact match then it sound like you want [templated DLS queries](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-and-document-access-control.html#templating-role-query) - I assume when you say _"Documents containing only corresponding Realm ID value"_ that you mean the docs themselves contain the value, and we're not talking about the name of the index, or anything like that.

---

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [July 4, 2024, 1:39pm UTC](https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371/3 "2024-07-04T13:39:10Z")

</div>

Hello @TimV ,  
Thank you for your reply.

What I am trying to reach is: dynamically map realm id value that is available in token claim to realm id value in document. For example, when user logs into Kibana he/she is able to see only data (documents) containing that specific realm id.

Currently I have configured role and role mapping as in examples below. I want to understand how it could be done automatically - more like in one generic role and role mapping. Without need to create many roles and role mappings with static values.

Role

```auto
PUT /_security/role/example-user
{
  "indices": [
    {
      "names": ["filebeat-*"],
      "privileges": ["read"],
      "field_security": {
         "grant": ["*"],
         "query": {"term":{"labels.example-realm-id":"1234-abcd-1234-abcd"}}
      }
    }
  ],
  "applications": [
    {
      "application": "kibana-.kibana",
      "privileges": ["feature_discover.read"],
      "resources": ["space:example-space"]
    }
  ],
  "metadata": {
    "description": "Some description"
  }
}

```

and role mapping

```auto
PUT /_security/role_mapping/example-user-mapping
{
  "roles": ["example-user"],
  "enabled": true,
  "rules": {
    "all": [
      {
        "field": {
          "realm.name": "oidc10" 
        }
      },
      {
        "field": {
          "metadata.oidc(example_realm_id)": "1234-abcd-1234-abcd"
        }
      }
    ]
  },
  "metadata": {
    "description": "Some description"
  }
}

```

Also tried to replace  
`"query": {"term":{"labels.example-realm-id":"1234-abcd-1234-abcd"}}`  
with  
`"query": {"term":{"labels.example-realm-id":"{{_user.metadata.oidc(example_realm_id)}}"}}`  
but it did not work and not sure why (or what is missing there).

Is there any solution to achieve dynamic mapping between realm\_id from token claim to value in document?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 5, 2024, 6:48am UTC](https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371/4 "2024-07-05T06:48:27Z")

</div>

> [@s.buksa](#):
>
> ```auto
> "field_security": {
> "grant": ["*"],
> "query": {"term":{"labels.example-realm-id":"1234-abcd-1234-abcd"}}
> }
> 
> ```

That's not a valid role - `query` is not part of `field_security`.

> [@s.buksa](#):
>
> I want to understand how it could be done automatically

And I provided the answer above:

> it sounds like you want [templated DLS queries](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-and-document-access-control.html#templating-role-query)

> [@s.buksa](#):
>
> Also tried to replace  
> `"query": {"term":{"labels.example-realm-id":"1234-abcd-1234-abcd"}}`  
> with  
> `"query": {"term":{"labels.example-realm-id":"{{_user.metadata.oidc(example_realm_id)}}"}}`  
> but it did not work and not sure why (or what is missing there).

Did you put it inside a `template` as shown in the docs that I linked to?
