bamaer opened a new pull request, #8169:
URL: https://github.com/apache/hop/pull/8169
The Hop Server servlet is co-deployed under /hop/* inside the Hop Web webapp
but had no authorization: any authenticated session (including the READ_ONLY
role) could deploy and execute pipelines and workflows via the API, bypassing
the RBAC the RAP UI enforces. In the default open install (mode NONE) the same
endpoints were reachable unauthenticated.
- HopServerEndpointPermissionMapper (core): maps each /hop/* endpoint to the
Permission it requires.
- HopServerAuthorizationFilter (rap), mapped after the auth filters:
* BASIC/EXTERNAL/OAUTH2 - resolve the request principal's roles and
require the endpoint's permission; 403 otherwise. Unknown endpoints
default-deny so new servlets cannot silently widen the surface.
* NONE - no user identity, so the API is all-open or all-closed. Closed by
default (allowUnauthenticatedServerApi=false) so the default image does not
expose unauthenticated execution; opt in via the config flag,
HOP_WEB_ALLOW_UNAUTHENTICATED_SERVER_API, or the Security config UI.
- web.xml (web assembly and the EXTERNAL local-auth-config sample) register
the filter on /hop/*.
- Security -> General tab: checkbox for the NONE opt-in.
- Tests: mapper + filter unit tests; HopServerApiRbacTest (web-tests) drives
the endpoints per role over HTTP; manual curl scripts under
web-tests/api-checks.
- Docs: hop-web.adoc notes the /hop/* authorization and the NONE default.
Standalone hop-server and hop-rest are unchanged.
**Please** add a meaningful description for your change here
------------------------
Thank you for your contribution! Follow this checklist to help us
incorporate your contribution quickly and easily:
- [x] Run `mvn clean install apache-rat:check` to make sure basic checks
pass. A more thorough check will be performed on your pull request
automatically.
- [x] If you have a group of commits related to the same change, please
squash your commits into one and force push your branch using `git rebase -i`.
- [x] Mention the appropriate issue in your description (for example:
`addresses #123`), if applicable.
To make clear that you license your contribution under the [Apache License
Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
you have to acknowledge this by using the following check-box.
- [x] I hereby declare this contribution to be licensed under the [Apache
License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
- [ ] In any other case, please file an [Apache Individual Contributor
License Agreement](https://www.apache.org/licenses/icla.pdf).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]