mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-03-04 08:52:27 -05:00
SAML - users not deleted #925
Labels
No labels
AS
can't reproduce
can't reproduce
deployment
development
documentation
duplicate
duplicate
ee
enhancement
external
new driver
performance
third party issue
wait for response
wait for review
wontfix
x:Oracle
x:cassandra
x:clickhouse
x:db2
x:duckdb
x:greenplum
x:h2
x:h2gis
x:hana
x:hive
x:intersystems
x:kyuubi
x:maria
x:mongo
x:mysql
x:postgresql
x:presto
x:sql server
x:sqlite
x:teradata
x:trino
xf:accessibility
xf:administration
xf:authentication
xf:aws
xf:commit-mode
xf:connection
xf:data editor
xf:datatransfer
xf:dba
xf:driver management
xf:erd
xf:filters
xf:i18n
xf:i18n
xf:installer
xf:json
xf:ldap
xf:local config
xf:log viewer
xf:metadata
xf:metadata editor
xf:navigator
xf:okta
xf:query manager
xf:resource manager
xf:scripts
xf:sql editor
xf:tasks
xf:ui/uix
xo: Firefox
xo:eclipse
xo:internet explorer
xo:macos
xp:major
xrn:internal
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/cloudbeaver#925
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Vormillion on GitHub (May 28, 2025).
Hi,
We are using SAML for SSO with Azure AD. We can't use Azure AD integration as it fails if user has more than 100 groups in AD.
Everything works fine with SAML but Cloudbeaver is not contacting Azure to check if existing users in configured Azure groups (CB Teams) are still present in Azure.
As a result, if user accessed CB one time, when he was added in proper AD group, then he will be visible in CB as active user forever, doesn't matter if user was deleted from allowed group or was fully removed from AD.
@EvgeniaBzzz commented on GitHub (May 29, 2025):
Hi @Vormillion
Thank you for the report.
We will add unmapping from CB groups when a user is removed from a group by the provider.
Just to be clear. Do you mean removing user from all AD groups?
@Vormillion commented on GitHub (Jun 2, 2025):
Hi,
So there are two cases when CB should delete user or mark is as disabled.