# Role Template with reference to metadata property from Open ID Realm

**URL:** <https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 19, 2023, 1:05pm UTC](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869 "2023-05-19T13:05:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Artem\_Ruzak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/artem_ruzak/32/121209_2.png) [@Artem\_Ruzak](https://discuss.elastic.co/u/Artem_Ruzak)\
**Post date:** [May 19, 2023, 1:05pm UTC](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869/1 "2023-05-19T13:05:53Z")

</div>

Hello,  
we are having SSO solution implemented based with Keycloak and based on OpenID concept  
It is working well and we are able to assign roles by username or with reference to realm.name

As a next step I want to implement role mapping based on some metadata properties assigned to user in Keycloak. The value is added to user details and passed as part of the authorisation JWT token:

```auto
{
  "exp": 1684484836,
  "iat": 1684484536,
  "jti": "f293f1ae-d364-483a-9d5f-019dccd8d4c3",
  "iss": "https://sso.<redacted>",
  "aud": "account",
  "sub": "<redacted>",
  "typ": "Bearer",
  "azp": "backend",
  "session_state": "76182e18-20e5-490a-a417-5d451d75b63e",
  "acr": "1",
  "allowed-origins": [
    "/*"
  ],
  "realm_access": {
    "roles": [
      "default-roles-sas",
      "REPORT_MANAGER",
      "offline_access",
      "uma_authorization"
    ]
  },
  "resource_access": {
    "account": {
      "roles": [
        "manage-account",
        "manage-account-links",
        "view-profile"
      ]
    }
  },
  "scope": "profile backend-client-scope email",
  "sid": "<redacted>",
  "tenant_id": "Sim2",
  "email_verified": true,
  "name": "<redacted>Surname",
  "preferred_username": "<redacted>",
  "given_name": "<redacted>",
  "family_name": "<redacted>",
  "email": "<redacted>"
}

```

Note that we have in token attribute `tenant_id` (at the very bottom of the list) that I want to use when assigning role in role template.

How shall I reference this attribute in role mapping rules and in role template?

From documentation I understood it shall be referenced as 'metadata.tenant\_id' but when I try to apply it in simple rule it does not applied.

My current role mapping template (not working):

```auto
{
  "keycloak_tenant": {
    "enabled": true,
    "role_templates": [
      {
        "template": """{"source":"azv_logs"}""",
        "format": "string"
      }
    ],
    "rules": {
      "all": [
        {
          "field": {
            "realm.name": "oidc1"
          }
        },
        {
          "field": {
            "metadata.tenant_id": "*"
          }
        }
      ]
    },
    "metadata": {}
  }
}

```

---

<div class="post-metadata">

**Author:** ![Artem\_Ruzak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/artem_ruzak/32/121209_2.png) [@Artem\_Ruzak](https://discuss.elastic.co/u/Artem_Ruzak)\
**Post date:** [May 19, 2023, 7:59pm UTC](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869/2 "2023-05-19T19:59:13Z")

</div>

In case someone will stuck on it as well -- after testing several variants I figured out that correct notion would be `metadata.oidc(tenant_id)`

E.g. mapping rule:

```auto
{
  "keycloak_tenant": {
    "enabled": true,
    "role_templates": [
      {
        "template": """{"source":"{{metadata.oidc(tenant_id)}}_logs"}""",
        "format": "string"
      }
    ],
    "rules": {
      "all": [
        {
          "field": {
            "metadata.oidc(tenant_id)": "*"
          }
        }
      ]
    },
    "metadata": {}
  }
}

```

also note that same notion is used in role template value: `{{metadata.oidc(tenant_id)}}_logs`

Best Regards, Artem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2023, 7:59pm UTC](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869/3 "2023-06-16T19:59:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
