Azure / Azure/data-api-builder

Make X-MS-API-ROLE optional

Abierto
#1,240 11 comentarios 1 reacción 0 asignados Ver en GitHub
auth enhancement
Lenguaje dominante
C#
Estrellas
1.5k
Forks
370
Merge medio
3 d 22 h
PR fusionados (30 d)
9

Descripción

DAB currently requires developers to provide `'X-MS-API-ROLE' : 'admin'` as a header when making their requests. However, this is not intuitive for new users, and this is inconvenient for all developers. They expect the role to be used to be assumed as the highest priority, especially when they only consider RBAC (for ex, if I have both authenticated & admin, I want DAB to use admin assuming it has higher permissions).

RBAC should not require the specification of `'X-MS-API-ROLE' : 'admin'`.

I understand that the explanation provided to me was that, while we can determine the 'most permissive role' for RBAC that the user has (according to the permissions in the config), we cannot determine the most permissive policy in case a policy is applied to a role.

One method I propose is that, if policies apply to the specific query the customer made, we respect the order of the permissions as specified in the config file & match the first policy, with the option to override with the `X-MS-API-ROLE` header.

This solution would not remove any current functionality, while leaving the `X-MS-API-ROLE` header reserved for more advanced use cases (policy matching).

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

El issue no menciona archivos ni tests. Empieza rastreando el comportamiento existente de RBAC y de selección de políticas, y luego determina cómo deben interactuar el orden de permisos configurado y la sobrescritura de X-MS-API-ROLE. La tarea estará terminada cuando las solicitudes de RBAC funcionen sin el header, mientras que la coincidencia avanzada de políticas pueda seguir utilizándolo.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
csharp
Área
api, authorization, backend, security
Tipo de issue
Nueva funcionalidad
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Tranquilo
Claridad
Necesita aclaración
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.