Summary0010237: JWT 'sub' cannot be mapped to a Role

At the moment we are only able to map roles and groups claims in a JWT to a Role using the Identitiy Mapping criteriaTypes 'Role' and 'GroupId'.

There is no way to map 'sub' or 'iss' + 'sub' to a Role.

A proposal from Randy to solve this was to add a Identitiy Mapping criteriaTypes 'Claim' that allows us to map different Claims to a Role.

related to 0010235 assignedRandy Armstrong 10000-006: Mappings Clarifications for JWT Issued User Identity Tokens 


