New features
- 2026-06-12 New feature: inheriting authorisations in new applications
- 2026-06-12 New feature: use holder group in UID script
2026-06-12 New feature: inheriting authorisations in new applications
The new feature
Now, on the Application access tree page, when creating an entry point, a folder or an application, the authorizations from the parent folder are now inherited.
Bear in mind
Please note the following points:
- If there are multiple levels of folders, only the authorizations from the parent folder are inherited.
How to configure it?
The following components must be installed:
- Console 3.6.75 (or higher)
Let's look at an example
On our "‘Application access tree" page, there are two levels of folders.
The first folder contains the following authorisations.
The second folder contains the following authorisations, the "Manager" user is different.
Now, let’s create a new application in the second folder.
If we access it, we can see that it has the authorizations of its parent Folder.
2026-06-12 New feature: use holder group in UID script
The new feature
Now, on the Service provider configuration page, the holder group can now be used in the UID selection script.
Bear in mind
Please note the following points:
- If there are multiple levels of folders, only the authorizations from the parent folder are inherited.
How to configure it?
The following components must be installed:
- Federation addon 3.6.92 (or higher)
Let's look at an example
First of all, we check that we have a user with holder groups.
We can now confirm that the service provider has the option "" enabled.
We use the holderGroup attribute in the UID script.
Finally, we’re going to authenticate with the service provider and check the value of the UID attribute.