Sandor Molnar created KNOX-3397:
-----------------------------------

             Summary: Remove index suffix from actor groups header explicitly 
in AbstractAuthResource
                 Key: KNOX-3397
                 URL: https://issues.apache.org/jira/browse/KNOX-3397
             Project: Apache Knox
          Issue Type: Bug
          Components: Server
    Affects Versions: 3.0.0
            Reporter: Sandor Molnar
            Assignee: Sandor Molnar
             Fix For: 3.0.0


h3. Background

KNOX-3354 introduced a change in {{AbstractAuthResource}} that removes the 
index suffix from the actor groups header when roles are resolved. 
Specifically, when role lookup happens at the resource layer (rather than in 
the LDAP interceptors), the configured actor groups header is no longer 
postfixed. This is useful in environments where role lookup is configured 
locally.

h3. Problem

A topology may instead use the {{RemoteAuthFilter}} to authenticate requests, 
where the remote counterpart is configured for role lookup. In that case, 
{{remote.auth.group.header}} returns roles rather than groups. However, the 
{{KNOX-AUTH-SERVICE}} configured in the topology still emits the suffixed 
version of {{preauth.auth.header.actor.groups.prefix}}, causing a mismatch.

h3. Proposed change

To give operators explicit control over this behavior, we introduce a new 
configuration parameter:

{{preauth.auth.header.actor.groups}}

When this parameter is declared, it takes precedence over the existing 
{{preauth.auth.header.actor.groups.prefix}} parameter and is used directly as 
the groups header in the response (without any suffix).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to