Uploaded image for project: 'Kafka'
  1. Kafka
  2. KAFKA-4454

Authorizer should also include the Principal generated by the PrincipalBuilder.

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 0.10.0.1
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None

      Description

      Currently kafka allows users to plugin a custom PrincipalBuilder and a custom Authorizer.
      The Authorizer.authorize() object takes in a Session object that wraps KafkaPrincipal and InetAddress.
      The KafkaPrincipal currently has a PrincipalType and Principal name, which is the name of Principal generated by the PrincipalBuilder.
      This Principal, generated by the pluggedin PrincipalBuilder might have other fields that might be required by the pluggedin Authorizer but currently we loose this information since we only extract the name of Principal while creating KaflkaPrincipal in SocketServer.

      It would be great if KafkaPrincipal has an additional field "channelPrincipal" which is used to store the Principal generated by the plugged in PrincipalBuilder.

      The pluggedin Authorizer can then use this "channelPrincipal" to do authorization.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                mgharat Mayuresh Gharat
                Reporter:
                mgharat Mayuresh Gharat
              • Votes:
                0 Vote for this issue
                Watchers:
                5 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: