# Templated Roles with Open ID Realm

**URL:** <https://discuss.elastic.co/t/templated-roles-with-open-id-realm/205191>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 25, 2019, 6:24am UTC](https://discuss.elastic.co/t/templated-roles-with-open-id-realm/205191 "2019-10-25T06:24:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stongia](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@stongia](https://discuss.elastic.co/u/stongia)\
**Post date:** [October 25, 2019, 6:24am UTC](https://discuss.elastic.co/t/templated-roles-with-open-id-realm/205191/1 "2019-10-25T06:24:51Z")

</div>

I am trying to create the templated role, where I want to use the user metadata info to provide user with role access. I am using the document available at  
[https://www.elastic.co/blog/attribute-based-access-control-with-xpack](https://www.elastic.co/blog/attribute-based-access-control-with-xpack)

I am creating role as

```
PUT _security/role/d_client_policy
{ 
    "indices": [{
        "names": ["unified_incident_processed"],
        "privileges": ["read"],
        "query": {
            "template": {
                "source": "{\"bool\": {\"filter\": [{\"terms\": {\"CLIENT_ID\": {{#toJson}}_user.metadata.CLIENT_ID{{/toJson}}}}]}}"
            }
        }
    }]
}

```

As I am using OIDC as the IDP for the application I am trying to add the metadata info the role mapping of for the username as

```
PUT _security/role_mapping/oidc-kibana_29
{
  "roles": ["my_policy"],
  "enabled": true,
  "rules": { "all": [
        { "field": { "realm.name": "oidc1" } },
        { "field": { "username": "useremail@emailid.com" } }
  ] },
  "metadata": {
        "Client_ID": [2181, 3245, 2134]
  }
}

```

As all this configuration is done at the level of role mapping, in \_user this reference is not visible.

My Question is: how we can use the templated roles in with OpenID Realm kind of scenario?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 25, 2019, 6:36am UTC](https://discuss.elastic.co/t/templated-roles-with-open-id-realm/205191/2 "2019-10-25T06:36:02Z")

</div>

Please don't post unformatted code, logs, or configuration as it's very hard to read.

Instead, paste the text and format it with \</\> icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

It would be great if you could update your post to solve this.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 25, 2019, 6:41am UTC](https://discuss.elastic.co/t/templated-roles-with-open-id-realm/205191/3 "2019-10-25T06:41:25Z")

</div>

You cannot _put_ metadata in the user object in role mapping. When authenticating via OpenID Connect realm though, the user object will get all the OpenID Connect ID Token claims as metadata as we describe [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-user-metadata.html).

So, if your OP can provide this metadata values as an ID Token claim , i.e. named `XXXX` , then you would be able to use `_user.metadata.oidc(XXXX)` in your templated roles.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2019, 6:41am UTC](https://discuss.elastic.co/t/templated-roles-with-open-id-realm/205191/4 "2019-11-22T06:41:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
