Search Results :

×

How to Configure Attribute Based Redirection / Restriction Addon with SAML/OAuth in WordPress?

This guide walks you through the steps to configure the Attribute-Based Redirection / Restriction Addon with the miniOrange SAML or OAuth/OpenID Connect Single Sign-On (SSO) plugin. By following this guide, you can configure attribute-based rules to automatically redirect users to specific pages after login or restrict access based on the user attributes received from your Identity Provider (IdP), providing a secure and personalized login experience.

Configure Attribute-Based Redirection/Restriction Addon with SAML Single Sign-On (SSO) Plugin

  • miniOrange Attribute Based Login provides redirection to different pages after login, based on the user’s attributes stored in the usermeta table of WordPress.
  • We can also provide redirection based on the user’s attributes which exist in some other table of WordPress.
  • Let’s say you want users with the attribute userType as Student to get redirected to https://www.miniorange.com/student after login.
  • And you want the users with the attribute userType as Staff to get redirected to https://www.miniorange.com/staff after login.
  • Then you can provide the following mapping under Attribute Based Redirection section.
attribute based redirection

  • Now, if any user is having the userType meta key value as Student or Staff, will be redirected to the corresponding configured URL after login.
  • Regex to Match: You can also provide a regular expression for the attribute value. If the logging in user satisfies the mapped regex, they will be redirected to the configured URL after logging in.
  • Attribute Based Restriction:

    • miniOrange Attribute Based Login provides login restriction based on the user’s attributes sent by the Identity Provider.
    • Let’s say you only want the users having userType as Contributor and MemberTypeCode as 25, 26, 40, 41 or 45 to be able to login. Then you can provide the following mapping under Attribute Based Restriction section.
    attribute based redirection

    Note and Contact Us - Attribute Based Redirection Addon

    Note: You can provide semicolon separated values in case of multiple attribute values. In this case, the rule will behave like the OR condition, that is, if the attribute sent by the IDP has any of the semicolons separated values, the user will be allowed to log in.


    • Now, any user trying to login with the above set of attributes will be allowed to log in. But if they don’t have the above set of attributes, they will be redirected to a page configured in the Restricted user redirect URL section of the plugin.
    • Multi-valued Attributes: You can provide rules with duplicate attribute name. In this case, it will behave like the AND condition.
    multi value attribute

    • As per the above configuration, a user will be allowed to login only if the userType attribute sent by the IdP for that user has the values contributor and editor.

Configure Attribute-Based Redirection / Restriction Addon with OAuth Client Single Sign-On (SSO) Plugin

miniOrange Attribute-Based Login Addon provides Redirection and Restriction to different pages after login, based on the user’s attributes stored in the user meta table of WordPress.

Setup Attribute-Based Redirection

  • Go to the miniOrange Single Sign-On (SSO) plugin for WordPress. Select your OAuth provider from the list.
attribute base login Addon OAuth Client Single Sign On (SSO)

  • Complete the OAuth Provider configuration setup by referring to the setup guides from here. After you have saved the settings. Click on Test Configuration button. You can see the Attribute name and its value in the test configuration table.
attribute base login Addon OAuth Client Single Sign On (SSO)

  • Scroll down and click on the Attribute Mapping section. Under the Map Custom Attributes section enter the field meta name of your choice and enter the attribute name from the OAuth Provider test configuration table. (Refer to the below image)
  • Click on the Save Settings button to save your mapping.
Map Custom Attributes

  • Now, go to the Attribute-Based Login Addon. you can set redirection different pages after login based on the user attributes stored in the user meta table of WordPress under the Attribute-Based Redirection section.
  • Enter the User Meta value which we have entered into the OAuth client plugin's Custom Attribute section. Enter the attribute name-value from the test configuration table in the Regex to match field. (Priority will be given from top-to-bottom, the first attribute value to satisfy the regex will be redirected.)
  • Now, enter the redirect URL where you want the user to be redirected in the URL to redirect field and click on the Save button.
Enter redirect URL

  • The user will now be redirected to the relevant page after performing the Single Sign-On (sso) based on his roles.

Setup Attribute-Based Restriction

  • Go back to the addon and click on the Attribute-Based Restriction section.
Attribute Based Restriction tab

  • If you want to restrict your users from login in based on the attributes sent by OAuth Provider then enable the Login Restriction based on the following rules option.
Enable Login Restriction

  • Let’s say you only want the users having roles as a teacher to be able to log in, then enter the user Attribute Name and the Attribute Value.
  • You can provide semicolon-separated values in case of multiple attribute values. In this case, the rule will behave like the OR condition, that is, if the attribute sent by the IDP has any of the semicolons separated values, the user will be allowed to log in.
Enter Attribute and Value

  • In the Restricted user redirect URL field, enter the page URL where you want to redirect user and click on the Save button. If users don't satisfy the User Login Rules configured above, will be redirected to this URL without logging in to the site.
Restricted user redirect URL

  • As per the above configuration, a user will be allowed to login only if the roles attribute sent by the IDP for that user has the value Teacher.

In this guide, you have successfully configured the Attribute Based Redirection/Restriction Add-on with the miniOrange SAML or OAuth/OpenID Connect Single Sign-On (SSO) plugin, routing users to specific pages or restricting login access based on the attributes received from your Identity Provider. This solution ensures every user lands on the right page automatically after SSO, delivering a personalized journey while keeping unauthorized users away from restricted areas without any extra manual effort.




 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

We'll Reach Out to You at the Earliest!



ADFS_sso ×
Hello there!

Need Help? We are right here!

support