Replies: 4 comments
-
|
Hello @ad8-bdl , Currently in auth0-cli, you can perform a machine login by providing your client credentials. This allows you to configure your client with a specific client grant and set the desired scopes accordingly. By specifying the appropriate scopes for your client grant, you can enable non-admin role such as Viewer access for logs without requiring full Admin privileges. |
Beta Was this translation helpful? Give feedback.
-
|
Hi @ramya18101 ; I expect using client credentials would likely allow me to specify the desired scopes. However for interactive use where the person using Whilst creating a client for the TBC: people with Viewer roles need to be able to use |
Beta Was this translation helpful? Give feedback.
-
|
Internally, when accessing logs with viewer permissions, the Management API’s At this stage, We’d like to park this in discussions for now and gauge the community’s feedback.. Basis on traction, we can look into exploring it further and potentially include it in our roadmap. Thanks again for your feedback and for helping us improve the Auth0 CLI! |
Beta Was this translation helpful? Give feedback.
-
|
I was very surprised to find out today that logging in to the CLI as a user requires admin role on the tenant. Strong +1 for allowing other tenant members to sign in. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Checklist
Describe the problem you'd like to have solved
Seems that at present
auth0requires the Admin Role on a tenancy. It would be good to support other roles, e.g. Viewer access for logs.At present a Viewer role gets a failure message "We are not able to activate your device." from the
activateURL, and "User is not authorized.." from the CLI.Describe the ideal solution
I believe this would be accomplished by way of specifying the desired scopes at logon.
auth0 login --scopesis documented as adding the given scopes; there appears to be no means on reducing or explicitly expressing the desired scopes as is needed for the above.there needs to be an new option that allows explicitly setting scopes; ideally the existing option would be renamed to be
--add-scopesand the new option would then be--scopes--scopesas--scopes-add(deprecate--scopes), add--scopes-setand a--scopes-delfor good measure (i.e. where it's simpler to express what you want as the default set minus a few scopes)the default Admin Role requirement / presumption re. scopes should be documented
Alternatives and current workarounds
None.
Additional context
No response
Beta Was this translation helpful? Give feedback.
All reactions