Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-8736

REST endpoint authorization

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Icon: Enhancement Enhancement
    • Resolution: Done
    • Icon: Major Major
    • None
    • None
    • REST, Security, Server
    • None

      The REST endpoint does not use the authenticated user to access authz caches. We need to:

      • integrate with the ServerAuthenticationProvider as used by the Hot Rod endpoint so that we can use security callbacks and retrieve a fully populated subject (including groups). This should ultimately connect with Elytron.
      • add SecurityActions within the rest code
      • Return 403 forbidden where needed

              ttarrant@redhat.com Tristan Tarrant
              ttarrant@redhat.com Tristan Tarrant
              Archiver:
              rhn-support-adongare Amol Dongare

                Created:
                Updated:
                Resolved:
                Archived: