Feature/#1059 Enable RBAC Checks for Authenticated Users After JWT Validation#1277
Merged
jpgough-ms merged 15 commits intofinos:mainfrom May 28, 2025
Merged
Feature/#1059 Enable RBAC Checks for Authenticated Users After JWT Validation#1277jpgough-ms merged 15 commits intofinos:mainfrom
jpgough-ms merged 15 commits intofinos:mainfrom
Conversation
…rce, protected with admin scope
willosborne
reviewed
May 16, 2025
willosborne
reviewed
May 16, 2025
willosborne
reviewed
May 16, 2025
willosborne
reviewed
May 16, 2025
calm-hub/src/main/java/org/finos/calm/resources/UserAccessResource.java
Outdated
Show resolved
Hide resolved
willosborne
reviewed
May 16, 2025
calm-hub/src/main/java/org/finos/calm/security/CalmHubScopes.java
Outdated
Show resolved
Hide resolved
willosborne
reviewed
May 16, 2025
willosborne
reviewed
May 16, 2025
calm-hub/src/main/java/org/finos/calm/security/UserAccessValidator.java
Outdated
Show resolved
Hide resolved
willosborne
reviewed
May 16, 2025
calm-hub/src/main/java/org/finos/calm/security/UserAccessValidator.java
Outdated
Show resolved
Hide resolved
willosborne
reviewed
May 16, 2025
calm-hub/src/main/java/org/finos/calm/security/AccessControlFilter.java
Outdated
Show resolved
Hide resolved
willosborne
reviewed
May 16, 2025
calm-hub/src/main/java/org/finos/calm/security/UserAccessValidator.java
Outdated
Show resolved
Hide resolved
jpgough-ms
requested changes
May 21, 2025
calm-hub/src/test/java/org/finos/calm/domain/TestUserAccess.java
Outdated
Show resolved
Hide resolved
calm-hub/src/test/java/org/finos/calm/resources/TestUserAccessResourceShould.java
Show resolved
Hide resolved
willosborne
approved these changes
May 28, 2025
jpgough-ms
approved these changes
May 28, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR contains the following changes:
namespace:adminscopes.UserAccessvalidatorServiceto perform RBAC check for the incoming request.calm-hub-admin-app(a ClientId in KeyCloak) to be able to createuser-accessrecords forCalmUI/CalmCLIusers.authorization code flowgrant type, we require a headless browser container to be able to generate an access token that is encoded with the authorized username, but currently, in one of the integration tests, I have used the password grant to enrich the username in the JWT.Pending:
/calm/namespacesUserAccessaudit service to insert entries intoUserAccessAuditcollection on any changes to existingUserAccessrecords.THIS SOFTWARE IS CONTRIBUTED SUBJECT TO THE TERMS OF THE FINOS Corporate Contributor License Agreement.
THIS SOFTWARE IS LICENSED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT, ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. THIS SOFTWARE MAY BE REDISTRIBUTED TO OTHERS ONLY BY EFFECTIVELY USING THIS OR ANOTHER EQUIVALENT DISCLAIMER IN ADDITION TO ANY OTHER REQUIRED LICENSE TERMS.