How to use the Industrial Edge Device API for custom user authentication and role management on a WinCC Unified Comfort Panel

0
Summary of the issueI am developing a custom Edge App for a SIMATIC HMI Unified Comfort Panel and want to implement an application-internal login dialog. My goal is to authenticate the user and retrieve their assigned roles/permissions via the Industrial Edge Device API so that I can realize different authorization levels (e.g., Operator vs. Admin) dynamically within my Express backend.Specific Questions & Integration BlockersWinCC Runtime User Integration: Is it possible for a containerized Edge App to query or validate credentials against the local user store (UMAC) configured via TIA Portal for the WinCC Unified Runtime? If this local database is isolated from the Edge environment, what is the best practice to synchronize or federate users between WinCC Unified and the Industrial Edge Device layer?API Endpoint & Payload: What is the correct internal gateway URL (e.g., via the Edge App Gateway) and the exact JSON payload structure required to pass a username/password combination from my Express route and receive a valid session token/JWT?Role Evaluation: Once authenticated, how can the Express server securely decode or query the user's specific roles/permissions to unlock UI features?Steps to reproduce / Relevant detailsEngineering Software: TIA Portal V21Hardware: SIMATIC HMI Unified Comfort Panel (MTP Series) running the Industrial Edge Runtime.App Stack: Isolated Docker container running a Node.js/Express application.Current status: Stuck on finding the official way for internal authentication APIs inside the panel's container ecosystem.
asked
3 answers
1

Hello Ulrich Leinauer!


Unfortunately, it is not possible to use TIAP users in an Industrial Edge app running in Unified Comfort panel. There is no provider to use the users configured there neither possibility to synchronize or federate users from WinCC Unified and Industrial Edge.

answered
0

Hi Ulrich Leinauer,
You have users defined in WinCC Unified and you have a separate application running in Industrial Edge. You want to know whether the Edge application can reuse the WinCC Unified users and roles.

  • If it can, you need the official Siemens authentication API and its endpoint/request/response format.
  • After authentication, you also need a supported way to retrieve the user's roles, such as Operator or Admin, so your application can control which functions are available.

The key technical question is whether Siemens supports direct UMAC access from an Edge container, or whether authentication must go through an Edge/Unified authentication service or another supported identity mechanism.

answered
0

Hi everyone,


Thanks for the replies. It’s a shame that it doesn’t work, but at least now I know and don’t have to worry about it anymore. I guess I’ll just build my own login system.

Thanks again, everyone.


Best regards,

Uli

answered