keycloak-scim/server_admin/topics/users/attributes.adoc
Marek Posolda b34fb17029
KEYCLOAK-16468 Read-only user attributes (#1081)
(cherry picked from commit 4e505128a5b8d7f916a330bc0fef883da04a441b)
(cherry picked from commit 511b127bb36baed787da7cf2d88549bd14e5d0a9)

Co-authored-by: Stian Thorgersen <stianst@gmail.com>
2021-01-18 13:18:04 +01:00

16 lines
882 B
Text

[[_user-attributes]]
=== User Attributes
Beyond basic user metadata like name and email, you can store arbitrary user attributes. Choose a user to manage
then click on the `Attributes` tab.
.Users
image:{project_images}/user-attributes.png[]
Enter in the attribute name and value in the empty fields and click the `Add` button next to it to add a new field.
Note that any edits you make on this page will not be stored until you hit the `Save` button.
NOTE: Some attributes that are read-only and are not supposed to be updated by the administrators. This includes attributes, which are read-only
by design like for example `LDAP_ID`, which is filled automatically by the LDAP provider. Some other attributes should be read-only for
typical user administrators due to security reasons. See the details in the link:#_read_only_user_attributes[Threat model mitigation chapter].