Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix/23 ava distributioni 148 require accsess permision from kc remote user #163

Open
wants to merge 6 commits into
base: main
Choose a base branch
from

Conversation

kostobog
Copy link
Collaborator

@blcham
Fix partially kbss-cvut/23ava-distribution#148

Refactoring roles:

  • roles are in lowercase
  • use - instead of _ separator
  • change prefix to ff-

Method authorization rules (annotations) are using the hasRole expression in while the record manager is using hasAuthority expression. The difference is that the hasRole expression has a default role prefix which can be configured (ROLE_ is used when default role prefix is not configured) while hasAuthority does not have a prefix. For example:

  • hasRole("user") in this PR will check for authority ff-user
  • hasAuthority("user") in this PR will check for authority user

@kostobog kostobog requested a review from blcham October 21, 2024 12:32
Copy link
Contributor

@blcham blcham left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just see my suggestion

@blcham
Copy link
Contributor

blcham commented Nov 1, 2024

@kostobog I guess we cannot merge this PR as 23ava-distribution will stop working, right? If so I would just rebase and NOT MERGE!!! yet

@blcham
Copy link
Contributor

blcham commented Nov 6, 2024

@kostobog see my comment in PR

- role name n lowercase
- remove explicit prefix
- replace role literals with constant where possible
…rity provider

In SecurityConfig:
- fix configurable role prefix not set using GrantedAuthorityDefaults
- fix http authorization rules are defined with roles without prefix
In MainUserDetailsService
- Add default user role to authenticated user if security provider is "internal"
@kostobog kostobog force-pushed the fix/23-ava-distributioni-148-require-accsess-permision-from-kc-remote-user branch from 840a69b to f0c3278 Compare November 6, 2024 12:56
@kostobog
Copy link
Collaborator Author

kostobog commented Nov 7, 2024

@blcham
rolePrefix refactored, branch is rebased on main.

@kostobog
Copy link
Collaborator Author

kostobog commented Nov 7, 2024

@blcham
Yes, if we merge users in distribution will not be able to access fta-fmea. To make it work in the distribution, we only need to update roles and groups in keycloak. There is no need to configure fta-fmea backend unless we want to change the default rolePrefix=ff-.

@kostobog kostobog requested a review from blcham November 7, 2024 11:47
@blcham
Copy link
Contributor

blcham commented Nov 19, 2024

@kostobog please rebase

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants