Sandor Molnar created KNOX-3397:
-----------------------------------
Summary: Remove index suffix from actor groups header explicitly
in AbstractAuthResource
Key: KNOX-3397
URL: https://issues.apache.org/jira/browse/KNOX-3397
Project: Apache Knox
Issue Type: Bug
Components: Server
Affects Versions: 3.0.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.0.0
h3. Background
KNOX-3354 introduced a change in {{AbstractAuthResource}} that removes the
index suffix from the actor groups header when roles are resolved.
Specifically, when role lookup happens at the resource layer (rather than in
the LDAP interceptors), the configured actor groups header is no longer
postfixed. This is useful in environments where role lookup is configured
locally.
h3. Problem
A topology may instead use the {{RemoteAuthFilter}} to authenticate requests,
where the remote counterpart is configured for role lookup. In that case,
{{remote.auth.group.header}} returns roles rather than groups. However, the
{{KNOX-AUTH-SERVICE}} configured in the topology still emits the suffixed
version of {{preauth.auth.header.actor.groups.prefix}}, causing a mismatch.
h3. Proposed change
To give operators explicit control over this behavior, we introduce a new
configuration parameter:
{{preauth.auth.header.actor.groups}}
When this parameter is declared, it takes precedence over the existing
{{preauth.auth.header.actor.groups.prefix}} parameter and is used directly as
the groups header in the response (without any suffix).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)