Skip to content

RabbitMQ 4.1.0 Okta Integration monitoring role has admin privileges #13773

Closed Answered by michaelklishin
samragu asked this question in Questions
Discussion options

You must be logged in to vote

@samragu the ability to declare queues, exchanges, bindings ultimately comes from the permissions a user has, not its tag. Certain tags are necessary for certain management UI and HTTP API operations but tags control nothing outside of the management plugin, and specifically around authN and authZ chains.

Users labelled as monitoring do not have access to certain management UI features but they can have sufficient permissions to modify the topology, consume messages, and so on.

We will not troubleshoot OAuth 2 setups for non-paying users.

Besides extensive documentation that covers multiple IDPs there are examples for multiple IDPs and a troubleshooting guide.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by michaelklishin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants