Uploaded image for project: 'WildFly Elytron'
  1. WildFly Elytron
  2. ELY-1921

HTTP External Security Not Supported by Elytron

    XMLWordPrintable

Details

    • Feature Request
    • Resolution: Done
    • Major
    • 1.13.0.Final
    • 1.11.0.Final
    • None
    • None

    Description

      For legacy security, there's an EXTERNAL HTTP authentication mechanism (io.undertow.security.impl.ExternalAuthenticationMechanism) which performs no verification and simply uses the principal that was passed from the REMOTE_USER attribute by the AJP protocol. There is a "ClientLoginModule" in legacy security used as such: https://access.redhat.com/solutions/3465231. It is a requirement to add an equivalent of this EXTERNAL mechanism available in legacy and Elytron-SASL for Elytron-HTTP in order to migrate away from legacy security.

      Attachments

        Activity

          People

            aabdelsa Ashley Abdel-Sayed (Inactive)
            aabdelsa Ashley Abdel-Sayed (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: