# OIDC role mapping not working

**URL:** <https://discuss.elastic.co/t/oidc-role-mapping-not-working/350743>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 10, 2024, 12:29pm UTC](https://discuss.elastic.co/t/oidc-role-mapping-not-working/350743 "2024-01-10T12:29:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![natharran](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@natharran](https://discuss.elastic.co/u/natharran)\
**Post date:** [January 10, 2024, 12:29pm UTC](https://discuss.elastic.co/t/oidc-role-mapping-not-working/350743/1 "2024-01-10T12:29:12Z")

</div>

Hello all,

I'm experiencing a problem with role mapping after successful OIDC authentication. My OP provides ID Token where the following data about user can be found (copied from ES log):

```auto
\"resource_access\":{\"kibana\":{\"roles\":[\"administrator\"]}}

```

In accordance with ES documentation, I put the following line to OIDC realm definition in ES configuration (docker compose environment section):

```auto
- xpack.security.authc.realms.oidc.oidc1.claims.groups=resource_access.kibana.roles

```

And i created my role mapping like this:

```auto
PUT _security/role_mapping/oidc-users
{
  "enabled": true,
    "roles": [
      "superuser",
      "monitoring_user",
      "kibana_admin",
      "editor"
    ],
    "rules": {
      "all": [
        {"field": {"realm.name": "oidc1"}},
        {"field": {"groups": "administrator"}}
      ]
    }
}

```

However, this doesn't work. Replacing the "groups" in role mapping definition with "resource\_access.kibana.roles" also doesn't work. What does work is any other field from ID token, but I need to get to this specific array. Could someone please tell me how?

Thank you.

---

<div class="post-metadata">

**Author:** ![natharran](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@natharran](https://discuss.elastic.co/u/natharran)\
**Post date:** [January 11, 2024, 3:23pm UTC](https://discuss.elastic.co/t/oidc-role-mapping-not-working/350743/3 "2024-01-11T15:23:04Z")

</div>

Does Elasticsearch even support nested objects in OIDC ID Token? Is it able to parse them? I haven't found this information in the documentation.

---

<div class="post-metadata">

**Author:** ![natharran](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@natharran](https://discuss.elastic.co/u/natharran)\
**Post date:** [January 22, 2024, 10:28am UTC](https://discuss.elastic.co/t/oidc-role-mapping-not-working/350743/4 "2024-01-22T10:28:49Z")

</div>

OK, so I figured out that ES doesn't support nested objects in ID Token. Solved by propagating Keycloak user roles as top-level array.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2024, 10:29am UTC](https://discuss.elastic.co/t/oidc-role-mapping-not-working/350743/5 "2024-02-19T10:29:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
