[
https://issues.apache.org/jira/browse/KNOX-3397?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099391#comment-18099391
]
ASF subversion and git services commented on KNOX-3397:
-------------------------------------------------------
Commit 204d97bf3d4eb5368de3153583773d1d9598cb5c in knox's branch
refs/heads/master from Sandor Molnar
[ https://gitbox.apache.org/repos/asf?p=knox.git;h=204d97bf3 ]
KNOX-3397: Add preauth.auth.header.actor.groups to set actor groups header name
explicitly (#1329)
> Remove index suffix from actor groups header explicitly in
> AbstractAuthResource
> -------------------------------------------------------------------------------
>
> Key: KNOX-3397
> URL: https://issues.apache.org/jira/browse/KNOX-3397
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Affects Versions: 3.0.0
> Reporter: Sandor Molnar
> Assignee: Sandor Molnar
> Priority: Major
> Fix For: 3.0.0
>
> Time Spent: 0.5h
> Remaining Estimate: 0h
>
> h3. Background
> KNOX-3354 introduced a change in {{AbstractAuthResource}} that removes the
> index suffix from the actor groups header when roles are resolved.
> Specifically, when role lookup happens at the resource layer (rather than in
> the LDAP interceptors), the configured actor groups header is no longer
> postfixed. This is useful in environments where role lookup is configured
> locally.
> h3. Problem
> A topology may instead use the {{RemoteAuthFilter}} to authenticate requests,
> where the remote counterpart is configured for role lookup. In that case,
> {{remote.auth.group.header}} returns roles rather than groups. However, the
> {{KNOX-AUTH-SERVICE}} configured in the topology still emits the suffixed
> version of {{preauth.auth.header.actor.groups.prefix}}, causing a mismatch.
> h3. Proposed change
> To give operators explicit control over this behavior, we introduce a new
> configuration parameter:
> {{preauth.auth.header.actor.groups}}
> When this parameter is declared, it takes precedence over the existing
> {{preauth.auth.header.actor.groups.prefix}} parameter and is used directly as
> the groups header in the response (without any suffix).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)