How to use attribute parameter substitution for DLS when user is authenticated through SAML

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser):
Opensearch version 2.5

Describe the issue:
I have configured SAML authentication for opensearch. I want to configure DLS based on some user attribute of user which comes part of SAML response. There is no documentation for SAML. I can see the documentation below

Configuration:

Relevant Logs or Screenshots:

Hi @skhilar

Have you tried to use your LDAP user attribute name for the <NAME> parameter?

I tried using jwt, it did not work. Do I need to try using ${attr.ldap. ?

Hi @skhilar

As per the documentation below, you can use custom attributes for internal, jwt, proxy or ldap. So it is not possible to configure it for SAML.

If you need this feature, you can create a new issue.

If it is related to the security plugin running on top of the OpenSearch nodes, please create a new issue at the link below:

If it is related to the security plugin running on top of OpenSearch Dashboards, please create a new issue at the following link: