envoyproxy / envoyproxy/envoy

Question about validating two tokens in the headers and ignoring one header if not present.

Open
#34,308 1 comment 0 reactions 0 assignees View on GitHub
area/jwt_authn help wanted question
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 20h
Merged PRs (30d)
437

Description

**If you are reporting *any* crash or *any* potential security issue, *do not*
open an issue in this repo. Please report the issue via emailing
envoy-security@googlegroups.com where the issue will be triaged appropriately.**

*Title*: *validating two tokens in the headers and ignoring one header if not present.*

*Description*:
The requirement I have is to accept and additional token header named `X-originating-api-authorization`, validate it along with the default authorization header using same issuer but ignore the check if `X-originating-api-authorization` is not present.

I have tried to achieve this by using allow_missing: {} but it doesnt work.

Envoy config as follows:
rules:
- match: { prefix: "/" }
requires:
requires_all:
requirements:
- requires_any:
requirements:
- provider_name: xyz_auth_pageSize
- allow_missing: {}
- requires_any:
requirements:
- provider_name: xyz_auth0
- provider_name: xyz_abc_auth0

please help find a solution
[optional *Relevant Links*:]
https://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/filters/http/jwt_authn/v3/config.proto

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.