Sandor Molnar created KNOX-3456:
-----------------------------------
Summary: Enforce canActFor.groups in delegation policy via Knox
LDAP group lookup
Key: KNOX-3456
URL: https://issues.apache.org/jira/browse/KNOX-3456
Project: Apache Knox
Issue Type: Sub-task
Components: Server
Affects Versions: 3.1.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.1.0
As a platform operator, I want to define delegation policies that grant
exchange rights to LDAP groups rather than individual user lists, so that
access follows group membership without requiring Knox policy updates for each
user change.
ACCEPTANCE CRITERIA:
- When a policy has a non-empty groups list for who the actor can act for, Knox
checks whether the subject user is a member of any listed group using the Knox
LDAP service group lookup.
- With the LDAP roles-lookup interceptor configured, the group names returned
by the LDAP service match the AWC role names stored in the policy. No
additional mapping step is required.
- If LDAP is disabled and a policy has a non-empty groups list, the token
exchange returns server_error with a description directing the operator to
enable LDAP. The exchange does not silently deny with subject_not_allowed.
- If the LDAP group lookup call throws an exception, the exchange returns
server_error with a description, and the exception and stack trace are logged.
Integration test: a user who is a member of a policy group is authorized. A
user who is not a member is denied with access_denied.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)