# Swap the IDM to get multi tenancy

**URL:** <https://forum.flowable.org/t/swap-the-idm-to-get-multi-tenancy/2822>\
**Category:** Flowable Engine\
**Created:** [October 29, 2018, 1:52pm UTC](https://forum.flowable.org/t/swap-the-idm-to-get-multi-tenancy/2822 "2018-10-29T13:52:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mattydebie](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.flowable.org/mattydebie/32/910_2.png) [@mattydebie](https://forum.flowable.org/u/mattydebie)\
**Post date:** [October 29, 2018, 1:52pm UTC](https://forum.flowable.org/t/swap-the-idm-to-get-multi-tenancy/2822/1 "2018-10-29T13:52:57Z")

</div>

Hey there

We would like to implement multi tenancy in our IDM. This is because the process definitions in the flowable-admin should only be visible to the right tenants.  
In the screenshot below, the tenant _bacmads_ should only be able to view definitions of _bacmads_ and nothing else.  
 ![tenant_example_admin](https://cdck-file-uploads-canada1.s3.dualstack.ca-central-1.amazonaws.com/flex035/uploads/flowable/original/1X/858643ee66aaf35cfef7768126d46856f9480a83.png)

This is implemented on database level, but there seems to be no way of adding the tenant _ids_ to certain admins in the flowable-idm.

We thought of 2 ways to handle this:

- Extend the exisiting idm to show the tenant
- Extend flowable to handle different RemoteIdmServices (like KeyCloak)

The second option appears to be most ideal as this would provide more flexibility for authentication.

Any help or pointers in the right direction would be greatly appreciated.

Joram already told us that extending the RemoteIdmServices will not work for SSO, but flowable uses spring security, so as an example we could look into [https://github.com/vdenotaris/spring-boot-security-saml-sample](https://github.com/vdenotaris/spring-boot-security-saml-sample)

---

<div class="post-metadata">

**Author:** ![joram](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.flowable.org/joram/32/26_2.png) [@joram](https://forum.flowable.org/u/joram)\
**Post date:** [November 6, 2018, 9:00am UTC](https://forum.flowable.org/t/swap-the-idm-to-get-multi-tenancy/2822/2 "2018-11-06T09:00:51Z")

</div>

There’s indeed two things to this:

- The user logging in would need to have the tenant information (i.e. [https://github.com/flowable/flowable-engine/blob/master/modules/flowable-ui-common/src/main/java/org/flowable/ui/common/security/SecurityUtils.java](https://github.com/flowable/flowable-engine/blob/master/modules/flowable-ui-common/src/main/java/org/flowable/ui/common/security/SecurityUtils.java) would need to have a getCurrentTenantId() for example. The FlowableAppUser [https://github.com/flowable/flowable-engine/blob/master/modules/flowable-ui-common/src/main/java/org/flowable/ui/common/security/FlowableAppUser.java](https://github.com/flowable/flowable-engine/blob/master/modules/flowable-ui-common/src/main/java/org/flowable/ui/common/security/FlowableAppUser.java) already has a tenantId field). Once that’s in, all calls that go to the engine api’s would need to pass this tenantId to make them tenant-aware.

- “extending the RemoteIdmServices will not work for SSO”: indeed, the current setup uses a filter to check the cookie and uses the RemoteIdmService to fetch users. From a quick glance at the code, this whole Spring Security configuration would need to be swapped with something that goes against an SSO provider. Hence why I thought swapping the security config with the one from your link above would be a good starting point. Ideally this is a configurable setting such that people can switch (and ideally that would be a contribution ;-)). The end result is that a FlowableAppUser needs to be there after authentication, that’s what all the subsequent code expects.

---

<div class="post-metadata">

**Author:** ![mattydebie](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.flowable.org/mattydebie/32/910_2.png) [@mattydebie](https://forum.flowable.org/u/mattydebie)\
**Post date:** [November 19, 2018, 3:05pm UTC](https://forum.flowable.org/t/swap-the-idm-to-get-multi-tenancy/2822/3 "2018-11-19T15:05:09Z")

</div>

Hey Joram,  
thanks for the reply you have certainly pointed us to the right direction (we think).

The main requirement appeared to be multi-tenancy, so in stead of implementing our own SSO we tried your first alternative.

The modeler seemed to already take the tenant ID into account. When giving a user a tenant, all the models, definitions and deployments he creates, gets that tenant as well.

The admin, as showed above, was not tenant aware. So as proposed:

- I added the `getCurrentTenantId()` to the SecurityUtils
- I looked for one method that every `*ClientResource` used so that I could add the tenantId to the request.

Right now I changed the following in the **org.flowable.ui.admin.rest.client.AbstractClientResource** to add the tenantId to the requests:

```java
protected Map<String, String[]> getRequestParametersWithoutServerId(HttpServletRequest request) {
        Map<String, String[]> parameterMap = request.getParameterMap();
        Map<String, String[]> resultMap = new HashMap<>();
        resultMap.putAll(parameterMap);
        resultMap.remove(SERVER_ID);
+
+ if (SecurityUtils.getCurrentTenantId() != null) {
+ resultMap.put("tenantId", new String[] { SecurityUtils.getCurrentTenantId() });
+ }
+
        return resultMap;
    }

```

Is this an acceptable approach?  
Right now the tenant only gets added when you change the users’ tenant in the database yourself, so this is only ‘activated’ when you want it to. We can ofcourse add a feature flag as well, if requested.

Would this be accepted as a PR since some other users may like this as well. Ohterwhise we would need to provide a custom Flowable Build.

---

<div class="post-metadata">

**Author:** ![mattydebie](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.flowable.org/mattydebie/32/910_2.png) [@mattydebie](https://forum.flowable.org/u/mattydebie)\
**Post date:** [November 20, 2018, 3:20pm UTC](https://forum.flowable.org/t/swap-the-idm-to-get-multi-tenancy/2822/4 "2018-11-20T15:20:04Z")

</div>

I also configured the IDM so that it’s able to edit the users’ tenant (default = null).

![screenshot2](https://cdck-file-uploads-canada1.s3.dualstack.ca-central-1.amazonaws.com/flex035/uploads/flowable/original/1X/21e9b1088b8f5353be0328aa9d1a24bc3fceda7f.png) ![screenshot1](https://cdck-file-uploads-canada1.s3.dualstack.ca-central-1.amazonaws.com/flex035/uploads/flowable/original/1X/b7bf139a7bd79b39da89bac6af217689f040e49c.jpeg)

At the moment this is not configurable, so everyone who uses the IDM will see the Tenants from now on.  
I’ll try and put in a PR tomorrow.

Changes can be (re)viewed on [our fork on github](https://github.com/inuits/flowable-engine/tree/inuits-6.4.0).
