Sandor Molnar created KNOX-3456:
-----------------------------------

             Summary:  Enforce canActFor.groups in delegation policy via Knox 
LDAP group lookup
                 Key: KNOX-3456
                 URL: https://issues.apache.org/jira/browse/KNOX-3456
             Project: Apache Knox
          Issue Type: Sub-task
          Components: Server
    Affects Versions: 3.1.0
            Reporter: Sandor Molnar
            Assignee: Sandor Molnar
             Fix For: 3.1.0


As a platform operator, I want to define delegation policies that grant 
exchange rights to LDAP groups rather than individual user lists, so that 
access follows group membership without requiring Knox policy updates for each 
user change.

ACCEPTANCE CRITERIA:

- When a policy has a non-empty groups list for who the actor can act for, Knox 
checks whether the subject user is a member of any listed group using the Knox 
LDAP service group lookup.

- With the LDAP roles-lookup interceptor configured, the group names returned 
by the LDAP service match the AWC role names stored in the policy. No 
additional mapping step is required.

- If LDAP is disabled and a policy has a non-empty groups list, the token 
exchange returns server_error with a description directing the operator to 
enable LDAP. The exchange does not silently deny with subject_not_allowed.

- If the LDAP group lookup call throws an exception, the exchange returns 
server_error with a description, and the exception and stack trace are logged.

Integration test: a user who is a member of a policy group is authorized. A 
user who is not a member is denied with access_denied.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to