[ 
https://issues.apache.org/jira/browse/KNOX-3397?focusedWorklogId=1032359&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1032359
 ]

ASF GitHub Bot logged work on KNOX-3397:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 27/Jul/26 08:36
            Start Date: 27/Jul/26 08:36
    Worklog Time Spent: 10m 
      Work Description: smolnar82 opened a new pull request, #1329:
URL: https://github.com/apache/knox/pull/1329

   [KNOX-3397](https://issues.apache.org/jira/browse/KNOX-3397) - Allow the 
actor groups header name to be configured explicitly
   
   ## What changes were proposed in this pull request?
   
   [KNOX-3354](https://issues.apache.org/jira/browse/KNOX-3354) removed the 
index suffix from the actor groups header when roles are resolved at the 
resource layer (rather than in the LDAP interceptors), so that the configured 
actor groups header is not postfixed. This is useful in environments where role 
lookup is configured locally.
   
   However, a topology may instead use the RemoteAuthFilter to authenticate 
requests, where the remote counterpart is configured for role lookup. In that 
case remote.auth.group.header returns roles rather than groups, but the 
`KNOX-AUTH-SERVICE` configured in the topology still emits the suffixed version 
of `preauth.auth.header.actor.groups.prefix`, causing a mismatch.
   
   To give operators explicit control over this, this PR introduces a new 
configuration parameter in AbstractAuthResource: 
`preauth.auth.header.actor.groups`. When declared, it takes precedence over the 
existing `preauth.auth.header.actor.groups.prefix` parameter and is used 
directly as the groups header name in the response, without any index suffix.
   
   When the new parameter is not set, behavior is unchanged (fully backward 
compatible). The header-name selection logic was also extracted into a small 
private `createGroupsHeaderName(...)` helper for readability.
   
   ## How was this patch tested?
   
   - Added a unit test 
(PreAuthResourceTest#testExplicitGroupsHeaderTakesPrecedenceOverPrefix) that 
configures both the explicit header and a prefix, and verifies the explicit 
header is emitted directly, exactly once, with no index suffix.
   - Ran the full PreAuthResourceTest suite: Tests run: 9, Failures: 0, Errors: 
0, Skipped: 0.
   
   ## Integration Tests
   N/A
   
   ## UI changes
   N/A




Issue Time Tracking
-------------------

            Worklog Id:     (was: 1032359)
    Remaining Estimate: 0h
            Time Spent: 10m

> Remove index suffix from actor groups header explicitly in 
> AbstractAuthResource
> -------------------------------------------------------------------------------
>
>                 Key: KNOX-3397
>                 URL: https://issues.apache.org/jira/browse/KNOX-3397
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>    Affects Versions: 3.0.0
>            Reporter: Sandor Molnar
>            Assignee: Sandor Molnar
>            Priority: Major
>             Fix For: 3.0.0
>
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> h3. Background
> KNOX-3354 introduced a change in {{AbstractAuthResource}} that removes the 
> index suffix from the actor groups header when roles are resolved. 
> Specifically, when role lookup happens at the resource layer (rather than in 
> the LDAP interceptors), the configured actor groups header is no longer 
> postfixed. This is useful in environments where role lookup is configured 
> locally.
> h3. Problem
> A topology may instead use the {{RemoteAuthFilter}} to authenticate requests, 
> where the remote counterpart is configured for role lookup. In that case, 
> {{remote.auth.group.header}} returns roles rather than groups. However, the 
> {{KNOX-AUTH-SERVICE}} configured in the topology still emits the suffixed 
> version of {{preauth.auth.header.actor.groups.prefix}}, causing a mismatch.
> h3. Proposed change
> To give operators explicit control over this behavior, we introduce a new 
> configuration parameter:
> {{preauth.auth.header.actor.groups}}
> When this parameter is declared, it takes precedence over the existing 
> {{preauth.auth.header.actor.groups.prefix}} parameter and is used directly as 
> the groups header in the response (without any suffix).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to