smolnar82 opened a new pull request, #1402: URL: https://github.com/apache/knox/pull/1402
[KNOX-3456](https://issues.apache.org/jira/browse/KNOX-3456) - LDAP group lookup for canActFor.groups ## What changes were proposed in this pull request? KNOX-3441 landed the token-exchange delegation policy with the `canActFor.groups` branch left as a stub (`UnsupportedOperationException` → HTTP 501). This PR implements the group-membership check: - **Group lookup (AC1):** When the impersonated subject does not match `canActForUsers` and the policy's `canActForGroups` is non-empty, `JdbcDelegationPolicyService.evaluate()` resolves the subject's groups via `KnoxLDAPService.getUserGroups(subjectName)` and authorizes if any returned group is in the allowed set. Injected through `DelegationPolicyServiceFactory` (`ServiceType.LDAP_SERVICE`), mirroring `HadoopGroupProviderFilter`. - **No mapping step (AC2):** Group names from the LDAP service (role CNs, including bare-RDN roles surfaced by the roles-lookup interceptor) are compared directly against the stored policy groups — a plain set-membership test, no transformation. - **LDAP disabled/absent (AC3):** A group-based policy with LDAP absent or disabled is an operator misconfiguration, not a denial. It raises `DelegationGroupLookupUnavailableException`, which `TokenExchangeHandler` maps to HTTP 500 `server_error` with a description directing the operator to enable LDAP — rather than silently denying with `subject_not_allowed`. - **Lookup failure (AC4):** If the LDAP group lookup call itself throws, the exception and stack trace are logged (at ERROR) and re-raised as `DelegationGroupLookupUnavailableException` (chaining the cause), again surfaced as `server_error`. Ordering is unchanged otherwise: the group check runs last, after the cheaper user/resource/scope checks, and is skipped entirely when the subject already matches `canActForUsers`. ## How was this patch tested? Automated unit tests, all green: - `JdbcDelegationPolicyServiceTest` (58) — authorized-via-group, deny-when-in-no-group, user-check-short-circuits-group-lookup, and the three server_error paths (LDAP absent, LDAP disabled, lookup throws — the last asserting the originating exception is chained as the cause). - `TokenExchangeHandlerTest` (67) — `canActFor.groups` denial → 400 `invalid_request`; group-lookup-unavailable → 500 `server_error` with an LDAP-oriented description. - `DelegationPolicyServiceFactoryTest` (3) and `H2DBDelegationPolicyServiceTest` (2) confirm the LDAP service is wired in for both the H2 and JDBC paths. ## Integration Tests N/A -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
