hsheinblatt commented on code in PR #1270:
URL: https://github.com/apache/knox/pull/1270#discussion_r3606994033
##########
gateway-server/src/main/resources/conf/gateway-site.xml:
##########
@@ -218,4 +218,53 @@ limitations under the License.
</property>
-->
+ <!-- KnoxIDF Trusted OIDC Issuer Service Configuration
Review Comment:
Filed https://issues.apache.org/jira/browse/KNOX-3384 to track this task.
##########
gateway-server/src/main/resources/createKnoxIDFTrustedOidcIssuersTableOracle.sql:
##########
@@ -0,0 +1,23 @@
+-- Licensed to the Apache Software Foundation (ASF) under one or more
+-- contributor license agreements. See the NOTICE file distributed with this
+-- work for additional information regarding copyright ownership. The ASF
+-- licenses this file to you under the Apache License, Version 2.0 (the
+-- "License"); you may not use this file except in compliance with the
License.
+-- You may obtain a copy of the License at
+--
+-- http://www.apache.org/licenses/LICENSE-2.0
+--
+-- Unless required by applicable law or agreed to in writing, software
+-- distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+-- WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+-- License for the specific language governing permissions and limitations
under
+-- the License.
+
+CREATE TABLE TRUSTED_OIDC_ISSUERS (
+ issuer_url VARCHAR2(2048) NOT NULL,
+ dynamic_jwks NUMBER(1) DEFAULT 0 NOT NULL,
+ cluster_name VARCHAR2(256),
Review Comment:
Done, but in a new PR.
##########
gateway-spi/src/main/java/org/apache/knox/gateway/services/knoxidf/trustedoidcissuer/TrustedOidcIssuer.java:
##########
@@ -0,0 +1,63 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with this
+ * work for additional information regarding copyright ownership. The ASF
+ * licenses this file to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ * <p>
+ * http://www.apache.org/licenses/LICENSE-2.0
+ * <p>
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+ * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+ * License for the specific language governing permissions and limitations
under
+ * the License.
+ */
+package org.apache.knox.gateway.services.knoxidf.trustedoidcissuer;
+
+import java.time.Instant;
+
+public final class TrustedOidcIssuer {
+
+ private final String issuerUrl;
+ private final boolean dynamicJwks;
+ private final String clusterName;
+ private final Instant registeredAt;
+ private final String registeredBy;
+
+ public TrustedOidcIssuer(String issuerUrl, boolean dynamicJwks, String
clusterName,
+ Instant registeredAt, String registeredBy) {
+ this.issuerUrl = issuerUrl;
+ this.dynamicJwks = dynamicJwks;
+ this.clusterName = clusterName;
+ this.registeredAt = registeredAt;
+ this.registeredBy = registeredBy;
+ }
+
+ public String getIssuerUrl() {
+ return issuerUrl;
+ }
+
+ public boolean isDynamicJwks() {
+ return dynamicJwks;
+ }
+
+ /**
+ * @return the cluster name this issuer belongs to, or null if not
cluster-scoped
+ */
+ public String getClusterName() {
+ return clusterName;
+ }
+
+ public Instant getRegisteredAt() {
+ return registeredAt;
+ }
+
+ /**
+ * @return the identity that registered this issuer, or null if not recorded
+ */
+ public String getRegisteredBy() {
+ return registeredBy;
+ }
+}
Review Comment:
Yes. We try to pull the principal name from the request, but it may not be
defined. It's possible that practically it should always be or you've
configured security poorly, but in general I don't think we can guarantee the
API all would fail if it's not.
##########
gateway-server/src/main/resources/createKnoxIDFTrustedOidcIssuersTableDerby.sql:
##########
@@ -0,0 +1,22 @@
+-- Licensed to the Apache Software Foundation (ASF) under one or more
+-- contributor license agreements. See the NOTICE file distributed with this
+-- work for additional information regarding copyright ownership. The ASF
+-- licenses this file to you under the Apache License, Version 2.0 (the
+-- "License"); you may not use this file except in compliance with the
License.
+-- You may obtain a copy of the License at
+--
+-- http://www.apache.org/licenses/LICENSE-2.0
+--
+-- Unless required by applicable law or agreed to in writing, software
+-- distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+-- WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+-- License for the specific language governing permissions and limitations
under
+-- the License.
+
+CREATE TABLE TRUSTED_OIDC_ISSUERS (
+ issuer_url VARCHAR(2048) PRIMARY KEY,
+ dynamic_jwks BOOLEAN DEFAULT false,
+ cluster_name VARCHAR(256),
+ registered_at TIMESTAMP,
+ registered_by VARCHAR(2048)
+)
Review Comment:
Added, but in a new PR.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]