[midPoint] Allow to remove assigned roles from end user

mikhail.nikolaenko mikhail.nikolaenko at proton.me
Wed Apr 9 11:37:46 CEST 2025


Hello,

I am trying now RBAC and I have configured one end user with standard EndUser role which is available in the default installation. I even tried to add authorization with "<action>http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#unassign</action>" permission.

User can request roles (marked as requestable) but user can not remove them. On UI there is no "-" or any other menu I can find for that.

Can someone give me a hint what should I grant and to which object, so user can remove roles from its profile?

With best regards,
Mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20250409/3431347d/attachment.htm>


More information about the midPoint mailing list