This is an automated email from the ASF dual-hosted git repository. smolnar82 pushed a commit to branch knox_idf in repository https://gitbox.apache.org/repos/asf/knox.git
commit cd506ae79a0fb4b6794f590289653becbe2d5097 Author: Sandor Molnar <[email protected]> AuthorDate: Thu Jun 18 11:53:46 2026 +0200 KNOX-3354: Remove index suffix from actor groups header for roles in AbstractAuthResource (#1267) (cherry picked from commit f5fce559eea14a7f71580c0cb506f728c7a2aa27) --- .../gateway/service/auth/AbstractAuthResource.java | 6 ++++-- .../gateway/service/auth/ExtAuthzResourceTest.java | 3 +++ .../gateway/service/auth/PreAuthResourceTest.java | 24 ++++++++++++++-------- 3 files changed, 22 insertions(+), 11 deletions(-) diff --git a/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java b/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java index 3f91decd4..4e844d643 100644 --- a/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java +++ b/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java @@ -107,9 +107,11 @@ public abstract class AbstractAuthResource { .collect(Collectors.toSet()); final Collection<String> roles = lookupRoles(primaryPrincipalName, matchingGroupNames); if (!matchingGroupNames.isEmpty() || !roles.isEmpty()) { - final List<String> groupStrings = GroupUtils.getGroupStrings(roles.isEmpty() ? matchingGroupNames : roles, groupHeaderLengthLimit, groupHeaderSizeLimit); + final boolean useRoles = !roles.isEmpty(); + final List<String> groupStrings = GroupUtils.getGroupStrings(useRoles ? roles : matchingGroupNames, groupHeaderLengthLimit, groupHeaderSizeLimit); for (int i = 0; i < groupStrings.size(); i++) { - getResponse().addHeader(String.format(Locale.ROOT, ACTOR_GROUPS_HEADER_FORMAT, authHeaderActorGroupsPrefix, i + 1), groupStrings.get(i)); + final String headerName = useRoles ? authHeaderActorGroupsPrefix : String.format(Locale.ROOT, ACTOR_GROUPS_HEADER_FORMAT, authHeaderActorGroupsPrefix, i + 1); + getResponse().addHeader(headerName, groupStrings.get(i)); } } return ok().build(); diff --git a/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/ExtAuthzResourceTest.java b/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/ExtAuthzResourceTest.java index 8822d6cf4..9d093973d 100644 --- a/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/ExtAuthzResourceTest.java +++ b/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/ExtAuthzResourceTest.java @@ -119,6 +119,9 @@ public class ExtAuthzResourceTest { response.setHeader(AbstractAuthResource.DEFAULT_AUTH_ACTOR_ID_HEADER_NAME, USER_NAME); EasyMock.expectLastCall(); + response.addHeader(EasyMock.eq(AbstractAuthResource.DEFAULT_AUTH_ACTOR_GROUPS_HEADER_PREFIX), EasyMock.anyString()); + EasyMock.expectLastCall().anyTimes(); + EasyMock.replay(context, response, mockRolesService, mockGatewayServices); groups.forEach(group -> subject.getPrincipals().add(new GroupPrincipal(group))); diff --git a/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/PreAuthResourceTest.java b/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/PreAuthResourceTest.java index fe2e9b755..78c019d62 100644 --- a/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/PreAuthResourceTest.java +++ b/gateway-service-auth/src/test/java/org/apache/knox/gateway/service/auth/PreAuthResourceTest.java @@ -56,15 +56,15 @@ public class PreAuthResourceTest { subject.getPrincipals().add(new PrimaryPrincipal(USER_NAME)); } - private void configureCommonExpectations(String actorIdHeaderName) { + private void configureCommonExpectations(String actorIdHeaderName) throws Exception { configureCommonExpectations(actorIdHeaderName, null, Collections.emptySet()); } - private void configureCommonExpectations(String actorIdHeaderName, String groupsHeaderPrefix, Collection<String> groups) { + private void configureCommonExpectations(String actorIdHeaderName, String groupsHeaderPrefix, Collection<String> groups) throws Exception { configureCommonExpectations(actorIdHeaderName, groupsHeaderPrefix, groups, null); } - private void configureCommonExpectations(String actorIdHeaderName, String groupsHeaderPrefix, Collection<String> groups, GatewayServices gatewayServices) { + private void configureCommonExpectations(String actorIdHeaderName, String groupsHeaderPrefix, Collection<String> groups, GatewayServices gatewayServices) throws Exception { context = EasyMock.createNiceMock(ServletContext.class); EasyMock.expect(context.getInitParameter(PreAuthResource.AUTH_ACTOR_ID_HEADER_NAME)).andReturn(actorIdHeaderName).anyTimes(); EasyMock.expect(context.getInitParameter(PreAuthResource.AUTH_ACTOR_GROUPS_HEADER_PREFIX)).andReturn(groupsHeaderPrefix).anyTimes(); @@ -77,7 +77,18 @@ public class PreAuthResourceTest { EasyMock.expectLastCall(); } - if (!groups.isEmpty()) { + if (gatewayServices != null) { + EasyMock.expect(context.getAttribute(GatewayServices.GATEWAY_SERVICES_ATTRIBUTE)).andReturn(gatewayServices); + final LDAPRolesLookupService rolesLookupService = gatewayServices.getService(ServiceType.LDAP_ROLES_LOOKUP_SERVICE); + if (rolesLookupService != null && rolesLookupService.enabled()) { + Collection<String> roles = rolesLookupService.lookupRoles(USER_NAME, groups); + if (roles != null && !roles.isEmpty()) { + final String expectedGroupsHeaderPrefix = (groupsHeaderPrefix == null ? PreAuthResource.DEFAULT_AUTH_ACTOR_GROUPS_HEADER_PREFIX : groupsHeaderPrefix); + response.addHeader(EasyMock.eq(expectedGroupsHeaderPrefix), EasyMock.anyString()); + EasyMock.expectLastCall().anyTimes(); + } + } + } else if (!groups.isEmpty()) { groups.forEach(group -> subject.getPrincipals().add(new GroupPrincipal(group))); final int groupStringSize = calculateGroupStringSize(groups); final int expectedGroupHeaderCount = groupStringSize / 1000 + 1; @@ -89,11 +100,6 @@ public class PreAuthResourceTest { } } - if (gatewayServices != null) { - EasyMock.expect(context.getAttribute(GatewayServices.GATEWAY_SERVICES_ATTRIBUTE)).andReturn(gatewayServices); - - } - EasyMock.replay(context, request, response); }
