[
https://issues.apache.org/jira/browse/KNOX-3397?focusedWorklogId=1032359&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1032359
]
ASF GitHub Bot logged work on KNOX-3397:
----------------------------------------
Author: ASF GitHub Bot
Created on: 27/Jul/26 08:36
Start Date: 27/Jul/26 08:36
Worklog Time Spent: 10m
Work Description: smolnar82 opened a new pull request, #1329:
URL: https://github.com/apache/knox/pull/1329
[KNOX-3397](https://issues.apache.org/jira/browse/KNOX-3397) - Allow the
actor groups header name to be configured explicitly
## What changes were proposed in this pull request?
[KNOX-3354](https://issues.apache.org/jira/browse/KNOX-3354) removed the
index suffix from the actor groups header when roles are resolved at the
resource layer (rather than in the LDAP interceptors), so that the configured
actor groups header is not postfixed. This is useful in environments where role
lookup is configured locally.
However, a topology may instead use the RemoteAuthFilter to authenticate
requests, where the remote counterpart is configured for role lookup. In that
case remote.auth.group.header returns roles rather than groups, but the
`KNOX-AUTH-SERVICE` configured in the topology still emits the suffixed version
of `preauth.auth.header.actor.groups.prefix`, causing a mismatch.
To give operators explicit control over this, this PR introduces a new
configuration parameter in AbstractAuthResource:
`preauth.auth.header.actor.groups`. When declared, it takes precedence over the
existing `preauth.auth.header.actor.groups.prefix` parameter and is used
directly as the groups header name in the response, without any index suffix.
When the new parameter is not set, behavior is unchanged (fully backward
compatible). The header-name selection logic was also extracted into a small
private `createGroupsHeaderName(...)` helper for readability.
## How was this patch tested?
- Added a unit test
(PreAuthResourceTest#testExplicitGroupsHeaderTakesPrecedenceOverPrefix) that
configures both the explicit header and a prefix, and verifies the explicit
header is emitted directly, exactly once, with no index suffix.
- Ran the full PreAuthResourceTest suite: Tests run: 9, Failures: 0, Errors:
0, Skipped: 0.
## Integration Tests
N/A
## UI changes
N/A
Issue Time Tracking
-------------------
Worklog Id: (was: 1032359)
Remaining Estimate: 0h
Time Spent: 10m
> Remove index suffix from actor groups header explicitly in
> AbstractAuthResource
> -------------------------------------------------------------------------------
>
> Key: KNOX-3397
> URL: https://issues.apache.org/jira/browse/KNOX-3397
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Affects Versions: 3.0.0
> Reporter: Sandor Molnar
> Assignee: Sandor Molnar
> Priority: Major
> Fix For: 3.0.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> h3. Background
> KNOX-3354 introduced a change in {{AbstractAuthResource}} that removes the
> index suffix from the actor groups header when roles are resolved.
> Specifically, when role lookup happens at the resource layer (rather than in
> the LDAP interceptors), the configured actor groups header is no longer
> postfixed. This is useful in environments where role lookup is configured
> locally.
> h3. Problem
> A topology may instead use the {{RemoteAuthFilter}} to authenticate requests,
> where the remote counterpart is configured for role lookup. In that case,
> {{remote.auth.group.header}} returns roles rather than groups. However, the
> {{KNOX-AUTH-SERVICE}} configured in the topology still emits the suffixed
> version of {{preauth.auth.header.actor.groups.prefix}}, causing a mismatch.
> h3. Proposed change
> To give operators explicit control over this behavior, we introduce a new
> configuration parameter:
> {{preauth.auth.header.actor.groups}}
> When this parameter is declared, it takes precedence over the existing
> {{preauth.auth.header.actor.groups.prefix}} parameter and is used directly as
> the groups header in the response (without any suffix).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)