Skip to content

Latest commit

 

History

History
39 lines (35 loc) · 4.95 KB

SamlConfig.md

File metadata and controls

39 lines (35 loc) · 4.95 KB

SamlConfig

Properties

Name Type Description Notes
enabled bool Enable/Disable Saml authentication for the server [optional]
idp_cert str Identity Provider Certificate (provided by IdP) [optional]
idp_url str Identity Provider Url (provided by IdP) [optional]
idp_issuer str Identity Provider Issuer (provided by IdP) [optional]
idp_audience str Identity Provider Audience (set in IdP config). Optional in Looker. Set this only if you want Looker to validate the audience value returned by the IdP. [optional]
allowed_clock_drift int Count of seconds of clock drift to allow when validating timestamps of assertions. [optional]
user_attribute_map_email str Name of user record attributes used to indicate email address field [optional]
user_attribute_map_first_name str Name of user record attributes used to indicate first name [optional]
user_attribute_map_last_name str Name of user record attributes used to indicate last name [optional]
new_user_migration_types str Merge first-time saml login to existing user account by email addresses. When a user logs in for the first time via saml this option will connect this user into their existing account by finding the account with a matching email address by testing the given types of credentials for existing users. Otherwise a new user account will be created for the user. This list (if provided) must be a comma separated list of string like 'email,ldap,google' [optional]
alternate_email_login_allowed bool Allow alternate email-based login via '/login/email' for admins and for specified users with the 'login_special_email' permission. This option is useful as a fallback during ldap setup, if ldap config problems occur later, or if you need to support some users who are not in your ldap directory. Looker email/password logins are always disabled for regular users when ldap is enabled. [optional]
test_slug str Slug to identify configurations that are created in order to run a Saml config test [optional]
modified_at str When this config was last modified [optional]
modified_by str User id of user who last modified this config [optional]
default_new_user_roles list[Role] (Read-only) Roles that will be applied to new users the first time they login via Saml [optional]
default_new_user_groups list[Group] (Read-only) Groups that will be applied to new users the first time they login via Saml [optional]
default_new_user_role_ids list[int] (Write-Only) Array of ids of roles that will be applied to new users the first time they login via Saml [optional]
default_new_user_group_ids list[int] (Write-Only) Array of ids of groups that will be applied to new users the first time they login via Saml [optional]
set_roles_from_groups bool Set user roles in Looker based on groups from Saml [optional]
groups_attribute str Name of user record attributes used to indicate groups. Used when 'groups_finder_type' is set to 'grouped_attribute_values' [optional]
groups list[SamlGroupRead] (Read-only) Array of mappings between Saml Groups and Looker Roles [optional]
groups_with_role_ids list[SamlGroupWrite] (Read/Write) Array of mappings between Saml Groups and arrays of Looker Role ids [optional]
auth_requires_role bool Users will not be allowed to login at all unless a role for them is found in Saml if set to true [optional]
user_attributes list[SamlUserAttributeRead] (Read-only) Array of mappings between Saml User Attributes and Looker User Attributes [optional]
user_attributes_with_ids list[SamlUserAttributeWrite] (Read/Write) Array of mappings between Saml User Attributes and arrays of Looker User Attribute ids [optional]
groups_finder_type str Identifier for a strategy for how Looker will find groups in the SAML response. One of ['grouped_attribute_values', 'individual_attributes'] [optional]
groups_member_value str Value for group attribute used to indicate membership. Used when 'groups_finder_type' is set to 'individual_attributes' [optional]
bypass_login_page bool Bypass the login page when user authentication is required. Redirect to IdP immediately instead. [optional]
url str Link to get this item [optional]
can dict(str, bool) Operations the current user is able to perform on this object [optional]

[Back to Model list] [Back to API list] [Back to README]