hsheinblatt commented on code in PR #1270:
URL: https://github.com/apache/knox/pull/1270#discussion_r3606994033


##########
gateway-server/src/main/resources/conf/gateway-site.xml:
##########
@@ -218,4 +218,53 @@ limitations under the License.
     </property>
     -->
 
+    <!-- KnoxIDF Trusted OIDC Issuer Service Configuration

Review Comment:
   Filed https://issues.apache.org/jira/browse/KNOX-3384 to track this task.



##########
gateway-server/src/main/resources/createKnoxIDFTrustedOidcIssuersTableOracle.sql:
##########
@@ -0,0 +1,23 @@
+--  Licensed to the Apache Software Foundation (ASF) under one or more
+--  contributor license agreements. See the NOTICE file distributed with this
+--  work for additional information regarding copyright ownership. The ASF
+--  licenses this file to you under the Apache License, Version 2.0 (the
+--  "License"); you may not use this file except in compliance with the 
License.
+--  You may obtain a copy of the License at
+--
+--  http://www.apache.org/licenses/LICENSE-2.0
+--
+--  Unless required by applicable law or agreed to in writing, software
+--  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+--  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+--  License for the specific language governing permissions and limitations 
under
+--  the License.
+
+CREATE TABLE TRUSTED_OIDC_ISSUERS (
+    issuer_url    VARCHAR2(2048) NOT NULL,
+    dynamic_jwks  NUMBER(1)      DEFAULT 0 NOT NULL,
+    cluster_name  VARCHAR2(256),

Review Comment:
   Done, but in a new PR.



##########
gateway-spi/src/main/java/org/apache/knox/gateway/services/knoxidf/trustedoidcissuer/TrustedOidcIssuer.java:
##########
@@ -0,0 +1,63 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with this
+ * work for additional information regarding copyright ownership. The ASF
+ * licenses this file to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ * <p>
+ * http://www.apache.org/licenses/LICENSE-2.0
+ * <p>
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+ * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+ * License for the specific language governing permissions and limitations 
under
+ * the License.
+ */
+package org.apache.knox.gateway.services.knoxidf.trustedoidcissuer;
+
+import java.time.Instant;
+
+public final class TrustedOidcIssuer {
+
+  private final String issuerUrl;
+  private final boolean dynamicJwks;
+  private final String clusterName;
+  private final Instant registeredAt;
+  private final String registeredBy;
+
+  public TrustedOidcIssuer(String issuerUrl, boolean dynamicJwks, String 
clusterName,
+      Instant registeredAt, String registeredBy) {
+    this.issuerUrl = issuerUrl;
+    this.dynamicJwks = dynamicJwks;
+    this.clusterName = clusterName;
+    this.registeredAt = registeredAt;
+    this.registeredBy = registeredBy;
+  }
+
+  public String getIssuerUrl() {
+    return issuerUrl;
+  }
+
+  public boolean isDynamicJwks() {
+    return dynamicJwks;
+  }
+
+  /**
+   * @return the cluster name this issuer belongs to, or null if not 
cluster-scoped
+   */
+  public String getClusterName() {
+    return clusterName;
+  }
+
+  public Instant getRegisteredAt() {
+    return registeredAt;
+  }
+
+  /**
+   * @return the identity that registered this issuer, or null if not recorded
+   */
+  public String getRegisteredBy() {
+    return registeredBy;
+  }
+}

Review Comment:
   Yes. We try to pull the principal name from the request, but it may not be 
defined. It's possible that practically it should always be or you've 
configured security poorly, but in general I don't think we can guarantee the 
API all would fail if it's not.



##########
gateway-server/src/main/resources/createKnoxIDFTrustedOidcIssuersTableDerby.sql:
##########
@@ -0,0 +1,22 @@
+--  Licensed to the Apache Software Foundation (ASF) under one or more
+--  contributor license agreements. See the NOTICE file distributed with this
+--  work for additional information regarding copyright ownership. The ASF
+--  licenses this file to you under the Apache License, Version 2.0 (the
+--  "License"); you may not use this file except in compliance with the 
License.
+--  You may obtain a copy of the License at
+--
+--  http://www.apache.org/licenses/LICENSE-2.0
+--
+--  Unless required by applicable law or agreed to in writing, software
+--  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+--  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+--  License for the specific language governing permissions and limitations 
under
+--  the License.
+
+CREATE TABLE TRUSTED_OIDC_ISSUERS (
+    issuer_url    VARCHAR(2048) PRIMARY KEY,
+    dynamic_jwks  BOOLEAN DEFAULT false,
+    cluster_name  VARCHAR(256),
+    registered_at TIMESTAMP,
+    registered_by VARCHAR(2048)
+)

Review Comment:
   Added, but in a new PR.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to