diff --git a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java index c1ce13cff0..a4ea2d48c8 100644 --- a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java +++ b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java @@ -54,7 +54,12 @@ public class WebServiceAuthImpl implements DBWServiceAuth { if (CommonUtils.isEmpty(providerId)) { throw new DBWebException("Missing auth provider parameter"); } - if (!CBApplication.getInstance().isConfigurationMode()) { + boolean configMode = CBApplication.getInstance().isConfigurationMode(); + + if (configMode || webSession.hasPermission(DBWConstants.PERMISSION_ADMIN)) { + // Admin can authorize in any providers + } else { + // Check enabled auth providers String[] enabledAuthProviders = CBApplication.getInstance().getAppConfiguration().getEnabledAuthProviders(); if (enabledAuthProviders != null && !ArrayUtils.contains(enabledAuthProviders, providerId)) { throw new DBWebException("Authentication provider '" + providerId + "' is disabled"); @@ -64,7 +69,6 @@ public class WebServiceAuthImpl implements DBWServiceAuth { if (authProvider == null) { throw new DBWebException("Invalid auth provider '" + providerId + "'"); } - boolean configMode = CBApplication.getInstance().isConfigurationMode(); try { Map providerConfig = Collections.emptyMap();