# If Authorization is restricted, only users with affiliation=staff are allowed access
SAML_RESTRICT_AUTHORIZATION=true
```
The values for the IDP were obtained from https://samltest.id/download/#SAMLtests_IdP
The values for the required attributes were taken from discussions recorded in https://gitlab.ruhr-uni-bochum.de/FDM/rdm-system/antleaf-projectmanagement/-/issues/24#note_132494 and https://gitlab.ruhr-uni-bochum.de/FDM/rdm-system/antleaf-projectmanagement/-/issues/24#note_132512
If `SAML_RESTRICT_AUTHORIZATION` is set to `true`, only users with affiliation=staff are allowed access. See [note](https://gitlab.ruhr-uni-bochum.de/FDM/rdm-system/antleaf-projectmanagement/-/blob/main/Introduction/RUB%20RDMS%20Authentication%20and%20Authorization.md) and https://gitlab.ruhr-uni-bochum.de/FDM/rdm-system/antleaf-projectmanagement/-/issues/164
4. Reload the environment variables in the container
Bring the container down and up again
5. Test the service is regsitered with SAML test at https://samltest.id/start-sp-test/
* The destination resource is the callback URL. It works even without it.
This should redirect you to a login page within samltest
If at this point you get the message the service is not registered, please wait a few minutes. We had to wait about 5 minutes before it started working.
6. test with the SAML login on the rdms application
Visit [Login](https://rdms.cottagelabs.com/users/sign_in?locale=en) -> [Sign in with SAML](https://rdms.cottagelabs.com/users/auth/saml?locale=en)
It should redirect you to samltest, get you to add the username and password and redirect to Cottage labs RDMS application.
# RUB IdP
Some attributes might be requested via raw OID values, e.g. RUB IdP. See example [here](https://gitlab.ruhr-uni-bochum.de/FDM/rdm-system/rdms/-/blob/8c22e9148634561b78bc8271d202ccb2c27a5874/.env.template#L136)