[
https://issues.apache.org/jira/browse/ARTEMIS-2886?focusedWorklogId=496109&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-496109
]
ASF GitHub Bot logged work on ARTEMIS-2886:
-------------------------------------------
Author: ASF GitHub Bot
Created on: 06/Oct/20 18:56
Start Date: 06/Oct/20 18:56
Worklog Time Spent: 10m
Work Description: jbertram commented on pull request #3254:
URL: https://github.com/apache/activemq-artemis/pull/3254#issuecomment-704485887
Are you saying the change I proposed changes how `roles` is treated? As far
as I can tell the change I proposed has nothing to do with the `roles` passed
to `authorize`. It's only impacting the `address` parameter of `authorize`. Am
I wrong about that?
Aside from that, the basic idea here is that if there is an exact match for
the FQQN then I pass those roles to `authorize` otherwise I pass whatever roles
came from the bare address match. It should be pretty straight-forward.
My change *will* allow a new semantic. Namely, it will allow the FQQN to be
passed to `authorize` even if there isn't an exact match. I believe this is the
semantic change you asked for, no?
I am not seeing a problem here.
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]
Issue Time Tracking
-------------------
Worklog Id: (was: 496109)
Time Spent: 4h 50m (was: 4h 40m)
> Optimize security auth
> ----------------------
>
> Key: ARTEMIS-2886
> URL: https://issues.apache.org/jira/browse/ARTEMIS-2886
> Project: ActiveMQ Artemis
> Issue Type: Improvement
> Reporter: Justin Bertram
> Assignee: Justin Bertram
> Priority: Major
> Fix For: 2.16.0
>
> Time Spent: 4h 50m
> Remaining Estimate: 0h
>
> Both authentication and authorization will hit the underlying security
> repository (e.g. files, LDAP, etc.). For example, creating a JMS connection
> and a consumer will result in 2 hits with the *same* authentication request.
> This can cause unwanted (and unnecessary) resource utilization, especially in
> the case of networked configuration like LDAP.
> There is a rudimentary cache for authorization, but it is cleared *totally*
> every 10 seconds by default (controlled via the
> {{security-invalidation-interval setting}}), and it must be populated
> initially which still results in duplicate auth requests.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)