Attempting to add a new user to site w/ SAML authentication

Open
#831 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
42/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Quiet
Tech stack
python

Research direction

Start with the shown create_user function, TSC.UserItem, and server.users.add call, then reproduce the SAML and ServerDefault cases against the listed Tableau Server, Python, and TSC versions. Compare the resulting permissions and user-creation behavior; done when the cause of the SAML-specific 403034 response and the expected library behavior are established.

Written by the indexing model from the issue text.

Description

docs Server-Side Enhancement

Describe the bug
I have written a script that creates a batch of users based on json input. It works great with the exception of one caveat. My list of users only contains two users, and all users are created with SAML as their authentication method. When creating them, one of the users works fine, however one of them fails with the following error message. The user is still created, but is not created with "SAML" authentication. If I change the SAML authentication to ServerDefault, then everything works perfectly, and no exception is thrown. The only thing notable about the failing user is that every other site has the a username just like this one. This is essentially our global sso admin user.

403034: Forbidden
   	Only system administrators can add users to sites, query sites for user membership, or remove users from sites.

Versions
Details of your environment, including:

  • Tableau Server version - 20204.21.0114.0916
  • Python version - Python 3.9.2
  • TSC library version - 0.14.0

To Reproduce
Below is my code that is handling the user creation. I only listed the portion of code that is failing and the snippet for configuring the server connection. I am calling this with an email address for the username, a basic name, and a role of 'explorer'. The server connection is configured with the new site that I am provisioning users for.

# configuration for tableau
server = TSC.Server( server_url, use_server_version=True )
tableau_auth = TSC.TableauAuth( username, password, site_name )
....
# function for creating users
def create_user( server, tableau_auth, username, full_name, user_role ):
  with server.auth.sign_in( tableau_auth ):
    try:
      # Attempt to create New User
      new_user = TSC.UserItem( username, user_role, auth_setting='SAML' )
      user_item = server.users.add( new_user )
      print( f'New User was Created: {username}'"\n" )
   ....

Results

403034: Forbidden
   	Only system administrators can add users to sites, query sites for user membership, or remove users from sites.

NOTE: Be careful not to post user names, passwords, auth tokens or any other private or sensitive information.

Dominant language
Python
Stars
716
Forks
446
Avg merge
8d 8h
Merged PRs (30d)
2

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from tableau/server-client-python

All issues in tableau/server-client-python

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.