Skip to content

Mandates / machtigen phase 2: specify "category" for form and pass this to the identity provider #4972

Open
@sergei-maertens

Description

@sergei-maertens

Follow up from phase 1 - #3623

Now that we can store the authentication context / mandate details in the whole chain of applications from forms to Open Zaak, we can focus on the second phase which is to restrict forms to certain services.

A service is the atomic bit of possible authorization limitations. In particular, a mandate may only apply to one (or more) services rather than the authorizee being able to manage every service for the representee. These services are grouped in categories (e.g. Burgerzaken / Schuldhulpverlening / ... to name some possible concepts).

When mandates are enabled for a form, it should be possible to specify which category/group applies to it, and pass along this information to the identity provider so that they can act as gatekeeper and inform the user when their mandate doesn't cover the group/services that are specified.

Tasks

  • Figure out how and where these categories are defined.
  • Figure out how to expose these categories/services in Open Forms and specify them to the authentication plugin options.
  • Establish pattern on how to pass this information to the identity provider and ensure that tampering is not possible.

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions